Back to overview

CVE-2026-41283

CRITICAL
9.9
CVSS 3.1
Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Metadata

CVE ID
CVE-2026-41283
State
PUBLISHED
Assigner
mitre
Reserved
2026-04-20 00:00 UTC
Published
2026-06-04 00:00 UTC
Last updated
2026-07-15 00:59 UTC
Primary CWE
CWE-863
CWE-863 Incorrect Authorization
Vendor / Product
OpenStack / Mistral
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
OpenStack Mistral 20.0.0 < 20.1.1, 21.0.0, 22.0.0
Weakness (CWE)
CWESourceDescription
CWE-863 cna CWE-863 Incorrect Authorization
CWE-749 adp Exposed Dangerous Method or Function
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview