Description
In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.
Published: 2026-10-08
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

In OpenStack Mistral versions up to 23.0.0, the v2 API write paths have a flaw that lets an authenticated project member resolve a target resource through a query that can return a resource belonging to another project. The member can then write to that resource, allowing the rewriting or unpublishing of another project's public action definitions and environments. Additionally, a project administrator can create a workbook whose embedded ad‑hoc action or workflow name collides with a resource of another project. This collision moves the resource into the caller's project and causes the original owner’s subsequent updates to fail with server errors. The vulnerability enables unauthorized modification of other projects’ resources and can lead to data integrity and availability issues. It is identified as a privilege escalation flaw (CWE‑863).

Affected Systems

OpenStack Mistral – all releases through 23.0.0 that expose the Mistral API. The issue targets the API itself, affecting any deployment that allows external users to interact with the v2 write endpoints. The vulnerability exists only when the API is accessible; ordinarily installed but isolated instances are not exposed to the network.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability with moderate exploitability. EPSS data is unavailable and the flaw is not currently listed in the CISA KEV catalog, suggesting limited widespread exploitation to date. Affected attackers must be authenticated members of a project; the attack is conducted via the normal API call path. Because the vulnerability requires access to the project’s identity and write permissions, the primary risk is elevated privilege within the defined project domain. The call flow involves authenticating to the API, issuing a write request that targets another project’s resource via a query, and exploiting the resulting cross‑project write to alter or destroy data. The impact is localized to affected projects but could compromise the integrity of publicly shared resources across multiple tenants.

Generated by OpenCVE AI on October 8, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch for this vulnerability when it becomes available.
  • If an upgrade is not immediately possible, restrict exposure of the Mistral API to trusted networks by adjusting firewall or reverse‑proxy rules so that only authorized services can reach the endpoint.
  • Implement fine‑grained project‑level access controls so that write operations for resources are allowed only to the owning project; disallow cross‑project write permissions for authenticated users.

Generated by OpenCVE AI on October 8, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross-Project Write Authorization Bypass in OpenStack Mistral API

Thu, 08 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack mistral
Vendors & Products Openstack
Openstack mistral

Thu, 08 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openstack Mistral
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T17:41:29.934Z

Reserved: 2026-09-24T02:16:02.138Z

Link: CVE-2026-97147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T18:18:33.583

Modified: 2026-10-08T21:10:41.427

Link: CVE-2026-97147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:00:14Z

Weaknesses