CVE-2026-93860

NameCVE-2026-93860
DescriptionIn OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1150346

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mistral (PTS)bookworm, bookworm (security)15.0.0-1+deb12u1vulnerable
trixie (security), trixie20.0.0-2+deb13u1vulnerable
forky, sid23.0.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mistralsource(unstable)(unfixed)1150346

Notes

https://launchpad.net/bugs/2162789
https://security.openstack.org/ossa/OSSA-2026-044.html

Search for package or bug name: Reporting problems