Insecure Direct Object Reference in OpenStack Mistral API
CVE-2026-93860

7.1HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-93860?

In OpenStack Mistral versions up to 23.0.0, the /v2/maintenance API controller is vulnerable due to a lack of proper policy enforcement. This flaw enables any user with a valid Mistral token to manipulate the cluster-wide maintenance state without sufficient authorization. Specifically, users can pause processing of new workflows and execution objects, which may disrupt operations across all tenant projects until an intervention is made by an operator.

Affected Version(s)

Mistral 0 < 20.1.1

Mistral 21.0.0 < 21.0.1

Mistral 22.0.0 < 22.0.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.