CVE-2026-34612
Kestra, an open‑source orchestration platform, had a critical SQL injection flaw in its default Docker Compose deployment. The flaw allowed authenticated users to trigger arbitrary OS commands via a crafted GET request to /api/v1/main/flows/search. The issue is fixed in version 1.3.7.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Kestra, versions prior to 1.3.7, especially those deployed with the default docker‑compose setup.
Real-world impact
An attacker who can authenticate to the Kestra instance can run any operating system command on the host, effectively taking full control of the machine.
Why this severity
The CVSS score of 9.9 reflects the high impact of remote code execution, the low effort required, and the fact that the vulnerability is exploitable without user interaction once authenticated.
What to do about it
- 01Upgrade Kestra to version 1.3.7 or later.
- 02Restart the Kestra service to apply the update.
NVD-referenced vendor advisory
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/kestra-io/kestra/commit/392…patch
- github.com/kestra-io/kestra/releases/t…productrelease notes
- github.com/kestra-io/kestra/security/a…exploitmitigationvendor advisory