openstack-mistral: OpenStack Mistral: Arbitrary Remote Code Execution via exposed API endpoints
Published Jun 4, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.92%
Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Affected products
-
- Version 20.0.0StatusaffectedConstraints<20.1.1
- Version 21.0.0StatusaffectedConstraints-
- Version 22.0.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat OpenStack Platform 16.2
openstack-mistral
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | openstack-mistral | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Restrict network access to the OpenStack Mistral API to trusted internal networks or hosts. Configure firewall rules to limit inbound connections to the Mistral API port (typically 8989) from untrusted sources, ensuring the API is not exposed to the public internet. Example using `firewall-cmd` (adjust zones and ports as needed): `firewall-cmd --zone=public --remove-port=8989/tcp --permanent` `firewall-cmd --zone=internal --add-port=8989/tcp --permanent` `firewall-cmd --reload` This action may impact legitimate clients requiring external access to the Mistral API. A service reload or restart may be required for firewall changes to take full effect.
References (11)
- http://www.openwall.com/lists/oss-security/2026/06/03/14
- https://access.redhat.com/security/cve/CVE-2026-41283 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2484607 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34201 Advisory
- https://github.com/advisories/GHSA-9hfw-w3f4-c4p8 Advisory
- https://github.com/openstack/mistral/tags
- https://nvd.nist.gov/vuln/detail/CVE-2026-41283
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json
- https://security.openstack.org/ossa/OSSA-2026-020.html
- https://www.cve.org/CVERecord?id=CVE-2026-41283
- https://www.openwall.com/lists/oss-security/2026/06/03/14
Change history (0)
No recorded changes yet.