CISA Lists Kestra OSS Command Injection Flaw in Exploited Vulnerabilities Catalog

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-04
Category: technology
Source: CISA
Original source

CISA has added CVE-2026-49869, a Kestra OSS OS command injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This critical flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials, posing substantial risks to affected systems. Federal agencies are mandated to remediate this vulnerability promptly.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai