CVE-2026-49869: Kestra Kestra OSS
Kestra OSS包含一個OS指令注入弱點,可以讓一個未經認證的遠端攻擊者在沒有資質的情況下建立和執行任意的工作流程。
CISA (English)
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
- 廠商
- Kestra
- 產品
- Kestra OSS
- 漏洞
- Kestra OSS OS Command Injection Vulnerability
- 加入日期
- 2026年9月2日
- CISA 修補期限(美國聯邦機關)
- 2026年9月5日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-78, CWE-184, CWE-287, CWE-918
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02