CVE-2026-34612Disclosure(kestra / kestra)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kestra kestra systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authenticated, simply visiting a crafted link is enough to trigger the vulnerability. The injected payload is executed by PostgreSQL using COPY ... TO PROGRAM ..., which in turn runs arbitrary OS commands on the host. This issue has been patched in version 1.3.7.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kestra

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-03); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kestra

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-03: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-04: 1Technical Details · 2026-04-09: 104-0304-0404-09
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-041
Disclosure1
2026-04-091
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    CVE-2026-34612: A critical 10.0 flaw in Kestra allows RCE via SQL injection in label searches. Protect your orchestration server—update to v1.3.7 now! #Kestra #CyberSecurity #InfoSec #RCE #SQLi #DevOps #Vulnerability #PostgreSQL https://securityonline.info/kestra-vulnerability-cve-2026-34612-sql-injection-rce/ https://t.co/oUb1ze1Kb9

    Post summary

    The post announces a critical RCE vulnerability in Kestra via SQL injection and urges users to update to v1.3.7.

    03050393
    12.3K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34612: CRITICAL] Critical vulnerability in Kestra prior to version 1.3.7 allows SQL Injection leading to Remote Code Execution in the "GET /api/v1/main/flows/search" endpoint. Update to the latest ...#cve,CVE-2026-34612,#cybersecurity https://cvefind.com/CVE-2026-34612

    Post summary

    A critical SQL injection vulnerability in Kestra (pre‑1.3.7) enables remote code execution via the /api/v1/main/flows/search endpoint; users are advised to update to the latest release.

    0001056
    619 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34612 - Critical Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remo... https://www.thehackerwire.com/vulnerability/CVE-2026-34612/ https://t.co/Qs9PONcTJ6

    Post summary

    Kestra's pre‑1.3.7 docker‑compose deployment is vulnerable to a critical SQL injection that could allow remote code execution, as announced in the linked advisory.

    0000064
    164 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34612: Kestra: Remote Code Execution vi... PostgreSQL's COPY TO PROGRAM turns this SQLi into instant RCE - authenticated users just need to click a malicious link... https://zerodaysignal.com/vulnerability/CVE-2026-34612 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new remote code execution vulnerability (CVE-2026-34612) in Kestra has been disclosed, with details that PostgreSQL’s COPY TO PROGRAM can convert an SQL injection into instant RCE. The linked zero‑day signal page suggests that PoC material may be available.

    0000077
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkestrakestra---

Explore more