Workflow Membership API Flaw in OpenStack Mistral Affects Project Permissions
CVE-2026-93861
What is CVE-2026-93861?
In OpenStack Mistral versions up to 23.0.0, a flaw in the workflow membership API allows a project that has accepted a share of another project's private workflow to manipulate membership assignments incorrectly. This misconfiguration allows the accepting project to create a new membership tied to a third project, defaulting the project_id to the accepting project instead of the original workflow owner. Consequently, the owner loses visibility and control over this new membership, preventing them from deleting or managing access. This grants the third project unauthorized access to read and execute the owner's private workflows, effectively bypassing the intended permission structure, which only allows the original owner to manage their workflows and associated memberships.
Affected Version(s)
Mistral 0 < 20.1.1
Mistral 21.0.0 < 21.0.1
Mistral 22.0.0 < 22.0.1
