CVE-2026-41283 Details
Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
A vulnerability in OpenStack Mistral versions 20.0.0 prior to 20.1.1, 21.0.0, and 22.0.0 has been identified, allowing arbitrary remote code execution when the API is exposed. This issue arises because several Mistral API endpoints do not properly enforce access policies, enabling authenticated users to create public resources and upload arbitrary code. The uploaded code is executed on Mistral executor workers, where it can access sensitive data, including service credentials. The vulnerability was reported by Eduardo Gonzalez Gutierrez and Arnaud Morin from OVHcloud.
Users can upgrade to OpenStack Mistral versions 20.1.1, 21.0.1, or 22.0.1. Instructions for upgrading can be found in the OpenStack Mistral GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-749 | Exposed Dangerous Method or Function | redhat-SADP |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | CVE |
| Jun 4, 2026 | New CVE Received | [email protected] |