CVE-2026-41283: OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
(updated )
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
References
- access.redhat.com/security/cve/CVE-2026-41283
- bugzilla.redhat.com/show_bug.cgi?id=2484607
- github.com/advisories/GHSA-9hfw-w3f4-c4p8
- github.com/openstack/mistral/tags
- nvd.nist.gov/vuln/detail/CVE-2026-41283
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json
- security.openstack.org/ossa/OSSA-2026-020.html
- www.openwall.com/lists/oss-security/2026/06/03/14
Code Behaviors & Features
Detect and mitigate CVE-2026-41283 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →