The vulnerability allows an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. It is associated with CWE-78, CWE-184, CWE-287, and CWE-918. These classifications describe the technical nature of the weakness within the software architecture. It is unknown whether the vulnerability is used in known ransomware campaigns at this time.

Timeline

On September 2, 2026, the Cybersecurity and Infrastructure Security Agency assigned CVE-2026-49869 to an OS command injection vulnerability in Kestra OSS. On the same date, the agency noted that the vulnerability allows an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Also on September 2, 2026, the vulnerability was identified as associated with CWE-78, CWE-184, CWE-287, and CWE-918.

On September 2, 2026, CISA stated that it is unknown whether the vulnerability is used in known ransomware campaigns. The agency also announced on September 2, 2026, that it requires forensic triage for this vulnerability. Stakeholders were instructed on September 2, 2026, to apply mitigations in accordance with vendor instructions and comply with CISA Binding Operational Directive 26-04.

The due date for applying these mitigations was set for September 5, 2026. Additionally, on September 2, 2026, the directive specified that stakeholders must discontinue use of the product if mitigations are unavailable.

Why It Matters

The assignment of CVE-2026-49869 places Kestra OSS under a federal compliance mandate through CISA Binding Operational Directive 26-04. The requirement for stakeholders to discontinue use of the product if mitigations are unavailable establishes a strict operational boundary for organizations relying on this software. This directive ensures that systems exposed to unauthenticated remote execution risks are either secured or taken offline by the September 5, 2026 deadline.

The association with multiple Common Weakness Enumeration identifiers, including CWE-78 and CWE-918, indicates a complex technical vulnerability affecting core workflow execution functions. The mandate for forensic triage requires affected entities to investigate their systems for signs of exploitation. The uncertainty regarding the vulnerability's use in known ransomware campaigns necessitates proactive defense measures rather than reactive responses to confirmed attacks.