CVE-2026-38428Disclosure(kestra / kestra)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kestra

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
kestra

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-12: 4Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-12: 305-0505-0605-12
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Disclosure1
2026-05-124
Disclosure2General2
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-38428 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text only provides basic CVE metadata without any indications of exploits, patches, or active attacks.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-38428 (CVSS 9.8) — multiple products. CVE: CVE-2026-38428 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑38428 as a critical vulnerability with a CVSS 9.8 score; no PoC, exploit details, or mitigation steps are mentioned.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-38428 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Kestra v1.3.3 and before is vulnerable to SQL Injection.

    Post summary

    Kestra v1.3.3 and earlier are vulnerable to SQL injection (CVE‑2026‑38428), a critical 9.8 CVSS vulnerability.

    1000034
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-38428 Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an … https://www.cve.org/CVERecord?id=CVE-2026-38428

    Post summary

    Kestra versions prior to 1.3.3 are vulnerable to SQL injection due to unsanitized GET parameter concatenation. No PoC, exploit code, or patch information is provided in the text.

    00010162
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-38428-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text references a CVE advisory but contains no detailed information, exploit code, or actionable guidance.

    0000022
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-38428 SQL Injection Vulnerability in Kestra v1.3.3 and Earlier Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-38428

    Post summary

    A brief disclosure of CVE-2026-38428, an SQL injection vulnerability affecting Kestra v1.3.3 and earlier, with a link to a vulnerability detail page.

    0000044
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-38428 Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an … https://www.cve.org/CVERecord?id=CVE-2026-38428 ----- Traducción: CVE-2026-38428 Kes… http://infoflow.cloud`

    Post summary

    The post announces a SQL injection vulnerability in Kestra versions prior to 1.3.3, describing its technical cause and linking to the CVE record.

    0000036
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkestrakestra---

Explore more