Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
20.0.0 (semver) before 20.1.1
affected
21.0.0 (semver)
affected
22.0.0 (semver)
affected
Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Problem types
CWE-863 Incorrect Authorization
Product status
20.0.0 (semver) before 20.1.1
21.0.0 (semver)
22.0.0 (semver)
References
www.openwall.com/lists/oss-security/2026/06/03/14
github.com/openstack/mistral/tags
www.openwall.com/lists/oss-security/2026/06/03/14
security.openstack.org/ossa/OSSA-2026-020.html