Insecure Direct Object Reference in OpenStack Mistral API
CVE-2026-93860
7.1HIGH
What is CVE-2026-93860?
In OpenStack Mistral versions up to 23.0.0, the /v2/maintenance API controller is vulnerable due to a lack of proper policy enforcement. This flaw enables any user with a valid Mistral token to manipulate the cluster-wide maintenance state without sufficient authorization. Specifically, users can pause processing of new workflows and execution objects, which may disrupt operations across all tenant projects until an intervention is made by an operator.
Affected Version(s)
Mistral 0 < 20.1.1
Mistral 21.0.0 < 21.0.1
Mistral 22.0.0 < 22.0.1
