API Access Control Issue in OpenStack Mistral by OpenStack
CVE-2026-97147

7.2HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-97147?

In recent versions of OpenStack Mistral, an access control vulnerability in the v2 API write paths enables authenticated project members to manipulate resources belonging to other projects. This occurs through a flawed resolution of target objects that can inadvertently expose or alter another project's resources. Specifically, this vulnerability allows users to rewrite and un-publish public action definitions and environments of different projects, leading to potential disruptions in service. Moreover, project administrators can inadvertently create conflicting workflows when resource names overlap across projects, resulting in operational failures for the original resource owners. This issue primarily affects deployments that expose the Mistral API, necessitating prompt remediation to ensure resource security and integrity.

Affected Version(s)

Mistral 0 < 20.1.1

Mistral 21.0.0 < 21.0.1

Mistral 22.0.0 < 22.0.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.