CVE-2026-93858: Openstack Mistral

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.

Affected products

  • Openstack Mistral: before 20.1.1 (fixed in 20.1.1); from 21.0.0, before 21.0.1 (fixed in 21.0.1); from 22.0.0, before 22.0.1 (fixed in 22.0.1); version 23.0.0 only

Published 2026-10-08. Last modified 2026-10-08.