CVE-2026-41283 PUBLISHED

Assigner: mitre
Reserved: 20.04.2026 Published: 04.06.2026 Updated: 04.06.2026

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor OpenStack
Product Mistral
Versions Default: unaffected
  • affected from 20.0.0 to 20.1.1 (excl.)
  • Version 21.0.0 is affected
  • Version 22.0.0 is affected

References

Problem Types

  • CWE-863 Incorrect Authorization CWE