API Access Control Issue in OpenStack Mistral by OpenStack
CVE-2026-97147
What is CVE-2026-97147?
In recent versions of OpenStack Mistral, an access control vulnerability in the v2 API write paths enables authenticated project members to manipulate resources belonging to other projects. This occurs through a flawed resolution of target objects that can inadvertently expose or alter another project's resources. Specifically, this vulnerability allows users to rewrite and un-publish public action definitions and environments of different projects, leading to potential disruptions in service. Moreover, project administrators can inadvertently create conflicting workflows when resource names overlap across projects, resulting in operational failures for the original resource owners. This issue primarily affects deployments that expose the Mistral API, necessitating prompt remediation to ensure resource security and integrity.
Affected Version(s)
Mistral 0 < 20.1.1
Mistral 21.0.0 < 21.0.1
Mistral 22.0.0 < 22.0.1
