CVE-2026-49869 in Kestra: internet exposure and the patch-to-KEV gap
Kestra was affected by CVE-2026-49869, an unauthenticated OS command injection rated 10.0 that allows remote code execution. The flaw was fixed in versions 1.0.45 and 1.3.21 released on 2–3 June 2026, and CISA added it to its KEV catalog on 2 September 2026. ZoomEye shows only hundreds of internet-facing instances, though most deployments are internal.
- CVE-2026-49869 is an unauthenticated command injection rated 10.0
- Fixed in Kestra 1.0.45 and 1.3.21 on 2–3 June 2026
- CISA added the flaw to KEV on 2 September 2026
- ZoomEye: 124 matches for app="Kestra", 234 for title="Kestra"
Read next
Security