Kestra OSS CVE-2026-49869 enters KEV: unauthenticated workflow execution leads to RCE
Published 09 Sep 2026 · Severity: critical
CISA added Kestra OSS CVE-2026-49869 to KEV on 2 September 2026. In affected default Basic Auth deployments, an unauthenticated attacker with network access can create and execute a workflow, leading to command execution inside the worker container. Upgrade to a patched Kestra release and investigate exposed or reachable instances.