CVE-2026-41283

CRITICAL

Openstack Mistral - Incorrect Authorization

Title source: rule
STIX 2.1

Description

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Scores

CVSS v3 9.9
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (3)
OpenStack/Mistral 20.0.0 - 20.1.1
OpenStack/Mistral 21.0.0
OpenStack/Mistral 22.0.0
Published Jun 04, 2026
Tracked Since Jun 04, 2026