Impact
In OpenStack Mistral versions up to 23.0.0, the v2 API write paths have a flaw that lets an authenticated project member resolve a target resource through a query that can return a resource belonging to another project. The member can then write to that resource, allowing the rewriting or unpublishing of another project's public action definitions and environments. Additionally, a project administrator can create a workbook whose embedded ad‑hoc action or workflow name collides with a resource of another project. This collision moves the resource into the caller's project and causes the original owner’s subsequent updates to fail with server errors. The vulnerability enables unauthorized modification of other projects’ resources and can lead to data integrity and availability issues. It is identified as a privilege escalation flaw (CWE‑863).
Affected Systems
OpenStack Mistral – all releases through 23.0.0 that expose the Mistral API. The issue targets the API itself, affecting any deployment that allows external users to interact with the v2 write endpoints. The vulnerability exists only when the API is accessible; ordinarily installed but isolated instances are not exposed to the network.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability with moderate exploitability. EPSS data is unavailable and the flaw is not currently listed in the CISA KEV catalog, suggesting limited widespread exploitation to date. Affected attackers must be authenticated members of a project; the attack is conducted via the normal API call path. Because the vulnerability requires access to the project’s identity and write permissions, the primary risk is elevated privilege within the defined project domain. The call flow involves authenticating to the API, issuing a write request that targets another project’s resource via a query, and exploiting the resulting cross‑project write to alter or destroy data. The impact is localized to affected projects but could compromise the integrity of publicly shared resources across multiple tenants.
OpenCVE Enrichment