PatchSiren cyber security CVE debrief
CVE-2026-38428 Kestra CVE debrief
CVE-2026-38428 is a SQL injection vulnerability in Kestra versions 1.3.3 and before. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical. Users of Kestra versions 1.3.3 and before should be aware of this vulnerability and take steps to mitigate it.
- Vendor
- Kestra
- Product
- Kestra
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-05
- Advisory updated
- 2026-07-24
Who should care
Users of Kestra versions 1.3.3 and before should be aware of this vulnerability and take steps to mitigate it. This vulnerability has a CVSS score of 9.8 and is considered critical. The vulnerability can be exploited by injecting malicious SQL code into the database query.
Technical summary
The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical. The vulnerability can be exploited by injecting malicious SQL code into the database query.
Defensive priority
High, given the CVSS score of 9.8 and the potential for significant impact on Kestra deployments if exploited. Users should prioritize patching or mitigating this vulnerability as soon as possible to prevent potential attacks. Implementing input validation and sanitization for user-controlled input can help prevent similar vulnerabilities in the future. Additionally, monitoring database queries for suspicious activity and considering compensating controls such as web application firewalls can help detect and prevent potential attacks. Regularly reviewing and updating Kestra deployments can also help ensure that they are secure and up-to-date. Furthermore, conducting regular security audits and penetration testing can help identify potential vulnerabilities and weaknesses in Kestra deployments. By taking these steps, users can help protect their Kestra deployments from potential attacks and ensure the security and integrity of their data. It is also recommended to track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Rollback change windows and source tracking can also be considered to ensure the security of Kestra deployments. Compensating controls such as web application firewalls can be implemented to detect and prevent potential attacks. Asset inventory and exposure review can help identify potential vulnerabilities and weaknesses in Kestra deployments. By prioritizing these defensive measures, users can help protect their Kestra deployments from potential attacks and ensure the security and integrity of their data. The vulnerability can be mitigated by applying vendor patches or updates to Kestra versions 1.3.3 or earlier, implementing input validation and sanitization for user-controlled input, monitoring,
Recommended defensive actions
- Inventory and assess Kestra installations for version 1.3.3 or earlier
- Apply vendor patches or updates to Kestra versions 1.3.3 or earlier
- Implement input validation and sanitization for user-controlled input
- Monitor database queries for suspicious activity
- Consider compensating controls such as web application firewalls
Evidence notes
The CVE record was published on 2026-05-05T19:16:21.910Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability occurs in Kestra versions 1.3.3 and before, and user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical.
Official resources
-
CVE-2026-38428 CVE record
CVE.org
-
CVE-2026-38428 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Mitigation, Vendor Advisory
-
Source reference
[email protected] - Not Applicable
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T19:16:21.910Z and has not been modified since then. The NVD entry is currently Analyzed.