Back

CRITICAL

openstack-mistral: OpenStack Mistral: Arbitrary Remote Code Execution via exposed API endpoints

Published Jun 4, 2026

Description

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Affected products

Remediation

Red Hat mitigation

Restrict network access to the OpenStack Mistral API to trusted internal networks or hosts. Configure firewall rules to limit inbound connections to the Mistral API port (typically 8989) from untrusted sources, ensuring the API is not exposed to the public internet. Example using `firewall-cmd` (adjust zones and ports as needed): `firewall-cmd --zone=public --remove-port=8989/tcp --permanent` `firewall-cmd --zone=internal --add-port=8989/tcp --permanent` `firewall-cmd --reload` This action may impact legitimate clients requiring external access to the Mistral API. A service reload or restart may be required for firewall changes to take full effect.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 4, 2026
Updated Jul 15, 2026
Reserved Apr 20, 2026
CISA Vulnrichment
Updated Jun 4, 2026
NVD
Status Awaiting Analysis
Modified Jul 22, 2026
Red Hat
Severity Important
Public date Jun 4, 2026
ENISA EUVD
Assigner mitre
Published Jun 4, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-34201 GHSA-9HFW-W3F4-C4P8