CISA Adds Kestra OSS Vulnerability to Actively Exploited Vulnerabilities List

CVE-2026-49869 allows unauthenticated attackers to bypass Basic Auth, create workflows and, under certain conditions, execute commands in the worker. Versions 1.0.45 and 1.3.21 fix the issue.




