PT-2026-46137 · Openstack · Mistral

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-41283

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-41283

Affected Products

Mistral