Workflow Membership API Flaw in OpenStack Mistral Affects Project Permissions
CVE-2026-93861

6MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-93861?

In OpenStack Mistral versions up to 23.0.0, a flaw in the workflow membership API allows a project that has accepted a share of another project's private workflow to manipulate membership assignments incorrectly. This misconfiguration allows the accepting project to create a new membership tied to a third project, defaulting the project_id to the accepting project instead of the original workflow owner. Consequently, the owner loses visibility and control over this new membership, preventing them from deleting or managing access. This grants the third project unauthorized access to read and execute the owner's private workflows, effectively bypassing the intended permission structure, which only allows the original owner to manage their workflows and associated memberships.

Affected Version(s)

Mistral 0 < 20.1.1

Mistral 21.0.0 < 21.0.1

Mistral 22.0.0 < 22.0.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.