Kestra Flaw Rated CVSS 10.0: Unauthenticated Root Code Execution, Now on CISA’s List
An authentication bypass in the Kestra workflow tool hands unauthenticated attackers code execution as root. CISA added CVE-2026-49869 to its exploited-vulnerabilities catalog on September 2.










