CVE-2026-34612 is a critical SQL Injection vulnerability affecting Kestra, an open-source orchestration platform, in versions prior to 1.3.7. This flaw allows an authenticated user to achieve Remote Code Execution (RCE) by visiting a crafted link targeting the /api/v1/main/flows/search endpoint, leveraging PostgreSQL's COPY ... TO PROGRAM ... function to execute arbitrary OS commands. Rated 9.9 Critical (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), it presents a network attack vector with low complexity, requiring only low privileges (an authenticated user) and no user interaction to achieve full system compromise. Although not currently listed in CISA's KEV catalog and with no public exploit code available, the vulnerability has received some community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.7CPE matchmatch criteria | cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.