Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-41283: OpenStack Mistral Remote Code Execution Risk
CVE-2026-41283
CVE-2026-41283
GHSA-9hfw-w3f4-c4p8
CVE-2026-41283
PYSEC-2026-3486
Summary
Mistral's API endpoints allow attackers to execute arbitrary code on a system, potentially stealing sensitive service credentials. This can happen if the API is exposed to the internet or an untrusted network. To mitigate this risk, ensure that the API is only accessible from trusted sources and consider implementing additional security measures such as authentication and access controls.
What to do
- Update mistral to version 20.1.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | openstack | mistral | < 20.1.1 |
| pip | – | mistral |
>= 20.0.0, < 20.1.1 21.0.0 22.0.0 Fix: upgrade to 20.1.1
|
| PyPI | – | mistral | All versions |
Original title
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
Original description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
nvd CVSS3.1
9.9
Vulnerability type
CWE-863
Incorrect Authorization
CWE-749
- https://github.com/openstack/mistral/tags
- https://www.openwall.com/lists/oss-security/2026/06/03/14
- https://security.openstack.org/ossa/OSSA-2026-020.html
- http://www.openwall.com/lists/oss-security/2026/06/03/14
- https://access.redhat.com/security/cve/CVE-2026-41283
- https://bugzilla.redhat.com/show_bug.cgi?id=2484607
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-41283
- https://github.com/advisories/GHSA-9hfw-w3f4-c4p8
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41283... Vendor Advisory
- https://github.com/openstack/mistral Product
- https://pypi.org/project/mistral Product
Published: 4 Jun 2026 · Updated: 6 Aug 2026 · First seen: 4 Jun 2026