{"total":1,"items":[{"id":172,"title":"CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability","original_title":"CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability","source_rating":null,"summary":"Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates ","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49869","type":"kev","language":"en","published_at":"2026-09-02T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Kestra"],"cves":[{"id":"CVE-2026-49869","cvss":10.0,"epss":0.02095,"epss_percentile":0.80993,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":10.0,"epss_max":0.02095,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null}]}