03 September 2026
Reference: CVE-2026-49869
1. What is being reported?
Kestra OSS has a bug in its security check that mistakenly allows anyone to access certain parts of the system without logging in. Because Kestra includes tools that can run scripts by default, attackers can use this to run any commands they want on the system where Kestra runs.
2. What this means in plain English
If your organisation uses Kestra OSS, attackers could take control of your system remotely without needing a password. This could lead to data loss, disruption, or other serious damage. The risk is high because this flaw is already being exploited by criminals.
3. Could this affect a small business?
Small organisations using Kestra OSS versions before 1.0.45 or 1.3.21 are at risk. If you do not use this software, or you use a later fixed version, you are probably not affected. Check with your IT provider if you are unsure.
4. What to do now
- Check if your organisation uses Kestra OSS and identify the version.
- If using an affected version, update Kestra OSS immediately to version 1.0.45 or 1.3.21 or later.
- If you cannot update right away, follow any temporary security measures recommended by Kestra or your IT provider.
- Review your systems for any unusual activity and ensure your security monitoring is active.
5. Ask your IT provider
Can you confirm if we use Kestra OSS, and if so, have we updated it to fix the known remote code execution vulnerability CVE-2026-49869?
6. Bottom line
If you use Kestra OSS, update it now to stop attackers from taking control of your system.
Information from CISA KEV, NVD, and reputable security reports.