HIGHVulnerability
Verified
Global
CISA KEV: Kestra Kestra OSS — Kestra OSS OS Command Injection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
Analysis
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-02. Remediation due: 2026-09-05.