PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-38428 Kestra CVE debrief

CVE-2026-38428 is a SQL injection vulnerability in Kestra versions 1.3.3 and before. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical. Users of Kestra versions 1.3.3 and before should be aware of this vulnerability and take steps to mitigate it.

Vendor
Kestra
Product
Kestra
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-07-24
Advisory published
2026-05-05
Advisory updated
2026-07-24

Who should care

Users of Kestra versions 1.3.3 and before should be aware of this vulnerability and take steps to mitigate it. This vulnerability has a CVSS score of 9.8 and is considered critical. The vulnerability can be exploited by injecting malicious SQL code into the database query.

Technical summary

The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical. The vulnerability can be exploited by injecting malicious SQL code into the database query.

Defensive priority

High, given the CVSS score of 9.8 and the potential for significant impact on Kestra deployments if exploited. Users should prioritize patching or mitigating this vulnerability as soon as possible to prevent potential attacks. Implementing input validation and sanitization for user-controlled input can help prevent similar vulnerabilities in the future. Additionally, monitoring database queries for suspicious activity and considering compensating controls such as web application firewalls can help detect and prevent potential attacks. Regularly reviewing and updating Kestra deployments can also help ensure that they are secure and up-to-date. Furthermore, conducting regular security audits and penetration testing can help identify potential vulnerabilities and weaknesses in Kestra deployments. By taking these steps, users can help protect their Kestra deployments from potential attacks and ensure the security and integrity of their data. It is also recommended to track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Rollback change windows and source tracking can also be considered to ensure the security of Kestra deployments. Compensating controls such as web application firewalls can be implemented to detect and prevent potential attacks. Asset inventory and exposure review can help identify potential vulnerabilities and weaknesses in Kestra deployments. By prioritizing these defensive measures, users can help protect their Kestra deployments from potential attacks and ensure the security and integrity of their data. The vulnerability can be mitigated by applying vendor patches or updates to Kestra versions 1.3.3 or earlier, implementing input validation and sanitization for user-controlled input, monitoring,

Recommended defensive actions

  • Inventory and assess Kestra installations for version 1.3.3 or earlier
  • Apply vendor patches or updates to Kestra versions 1.3.3 or earlier
  • Implement input validation and sanitization for user-controlled input
  • Monitor database queries for suspicious activity
  • Consider compensating controls such as web application firewalls

Evidence notes

The CVE record was published on 2026-05-05T19:16:21.910Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability occurs in Kestra versions 1.3.3 and before, and user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9.8 and is considered critical.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T19:16:21.910Z and has not been modified since then. The NVD entry is currently Analyzed.