CVE-2026-41283: Openstack Mistral
Critical severity, CVSS 9.9. EPSS: 0.9% chance of exploitation in the next 30 days.
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Affected products
- Openstack Mistral: from 20.0.0, before 20.1.1 (fixed in 20.1.1); version 21.0.0 only; version 22.0.0 only
- Red Hat Red Hat Openstack Platform 16.2
Published 2026-06-04. Last modified 2026-07-22.