CISA adds critical Kestra CVE-2026-49869 to KEV catalog
CISA added CVE-2026-49869 in the Kestra orchestration platform, rated 10.0, to its Known Exploited Vulnerabilities catalog. An authentication filter matched request paths by the /configs suffix instead of the exact route, allowing unauthenticated OS command injection; fixes shipped in 1.0.45 and 1.3.21 in June 2026.
- CVE-2026-49869 is unauthenticated OS command injection rated 10.0
- Root cause: auth filter matched paths by /configs suffix, not exact route
- Fixed in Kestra 1.0.45 and 1.3.21, released June 2–3, 2026
- CISA listed it in KEV on September 2, 2026 after evidence of exploitation
Read next
Security