PT-2026-46137 · Openstack+2 · Mistral+2

·

CVE-2026-41283

·

Published

2026-06-04

·

Updated

2026-07-23

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Mistral versions prior to 22.0.0
Description An issue exists where a policy enforcement bypass allows arbitrary remote code execution when the API is exposed. Specific API endpoints do not properly validate user-supplied inputs, enabling attackers to inject and execute malicious code on the hosting system without requiring authentication or user interaction. This can lead to the exfiltration of sensitive service credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41283
GHSA-9HFW-W3F4-C4P8
PYSEC-2026-3486
USN-8422-1

Affected Products

Linuxmint
Mistral
Ubuntu