Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. mistral
  4. ›
  5. CVE-2026-41283

CVE-2026-41283: OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

June 4, 2026 (updated July 14, 2026)

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

References

  • access.redhat.com/security/cve/CVE-2026-41283
  • bugzilla.redhat.com/show_bug.cgi?id=2484607
  • github.com/advisories/GHSA-9hfw-w3f4-c4p8
  • github.com/openstack/mistral/tags
  • nvd.nist.gov/vuln/detail/CVE-2026-41283
  • security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json
  • security.openstack.org/ossa/OSSA-2026-020.html
  • www.openwall.com/lists/oss-security/2026/06/03/14

Code Behaviors & Features

Detect and mitigate CVE-2026-41283 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 21.0.0, version 22.0.0, all versions starting from 20.0.0 before 20.1.1

Fixed versions

  • 20.1.1

Solution

Upgrade to version 20.1.1 or above.

Impact 9.9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-749: Exposed Dangerous Method or Function
  • CWE-863: Incorrect Authorization

Source file

pypi/mistral/CVE-2026-41283.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:06 +0000.