logo

10.0 CVSS Flaw in Kestra Grants Full Server Control

ID: 000f3d6b-1119-5306-884e-a2077cef1140

STIX ID: report--000f3d6b-1119-5306-884e-a2077cef1140

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical SQL injection (CVE-2026-34612) in Kestra (<= 1.3.6) stems from unparameterized search queries in the PostgresFlowRepositoryService; an authenticated attacker can inject stacked SQL to invoke PostgreSQL's COPY ... TO PROGRAM and run arbitrary OS commands, leading to complete host compromise and potential data exfiltration or ransomware; administrators are advised to apply the vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.