chiprook
← Security
SecuritySeptember 29, 2026, 07:20

CISA adds critical Kestra CVE-2026-49869 to KEV catalog

CISA added CVE-2026-49869 in the Kestra orchestration platform, rated 10.0, to its Known Exploited Vulnerabilities catalog. An authentication filter matched request paths by the /configs suffix instead of the exact route, allowing unauthenticated OS command injection; fixes shipped in 1.0.45 and 1.3.21 in June 2026.

CISA adds critical Kestra CVE-2026-49869 to KEV catalog
#Kestra#CISA
Read next
Security

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra

Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

Security

CISA Adds Linux Kernel CVE-2026-53266 to Known Exploited Vulnerabilities Catalog

Security

CISA adds Microsoft SharePoint and MikroTik RouterOS flaws to KEV catalog