Kestra OSS contains a critical OS command injection vulnerability tracked as CVE-2026-49869. The flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without any credentials. This represents a significant security risk as it requires no authentication to exploit. The vulnerability affects an open-source component that may be used by multiple products. CISA has flagged this under BOD 26-04, which prioritizes security updates based on risk. The advisory references the GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for additional technical details. Organizations using Kestra OSS are urged to apply security updates promptly. Forensic triage requirements are also outlined under BOD 26-04 implementation guidance.