Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-93858: OpenStack Mistral lets users run arbitrary commands via SSH proxy

CVE-2026-93858 · published 1 day ago
Summary

The Mistral workflow service in OpenStack (up to version 23.0.0) can be tricked into running any local command that a user supplies as a proxy setting. This means an authenticated user could cause the Mistral server to execute unwanted commands, even if the SSH connection itself fails. Disable the std.ssh_proxied action or upgrade to a version where the issue is fixed.

What to do
  • Update openstack mistral to version 20.1.1 or later.
Affected software
VendorProductAffected versions
openstack mistral < 20.1.1
Original advisory text
In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target hos...
In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-93858 · MITRE
Track software like this
Free during beta