Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-49869: Kestra Kestra OSS

Kestra OSS包含一個OS指令注入弱點,可以讓一個未經認證的遠端攻擊者在沒有資質的情況下建立和執行任意的工作流程。

CISA (English)

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

廠商
Kestra
產品
Kestra OSS
漏洞
Kestra OSS OS Command Injection Vulnerability
加入日期
2026年9月2日
CISA 修補期限(美國聯邦機關)
2026年9月5日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-78, CWE-184, CWE-287, CWE-918

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02