CVE-2026-93860: Openstack Mistral

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.

Affected products

  • Openstack Mistral: before 20.1.1 (fixed in 20.1.1); from 21.0.0, before 21.0.1 (fixed in 21.0.1); from 22.0.0, before 22.0.1 (fixed in 22.0.1); version 23.0.0 only

Published 2026-10-08. Last modified 2026-10-09.