Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41283

Опубликовано: 04 июн. 2026
Источник: redhat
CVSS3: 9.9

Описание

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

A flaw was found in OpenStack Mistral. When the API is exposed, a remote attacker can exploit certain endpoints to achieve arbitrary code execution. This allows the attacker to run malicious code on the system and potentially exfiltrate sensitive service credentials.

Меры по смягчению последствий

Restrict network access to the OpenStack Mistral API to trusted internal networks or hosts. Configure firewall rules to limit inbound connections to the Mistral API port (typically 8989) from untrusted sources, ensuring the API is not exposed to the public internet. Example using firewall-cmd (adjust zones and ports as needed): firewall-cmd --zone=public --remove-port=8989/tcp --permanent firewall-cmd --zone=internal --add-port=8989/tcp --permanent firewall-cmd --reload This action may impact legitimate clients requiring external access to the Mistral API. A service reload or restart may be required for firewall changes to take full effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2openstack-mistralNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-749
https://bugzilla.redhat.com/show_bug.cgi?id=2484607openstack-mistral: OpenStack Mistral: Arbitrary Remote Code Execution via exposed API endpoints

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
ubuntu
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

CVSS3: 9.9
nvd
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

CVSS3: 9.9
debian
2 месяца назад

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Executio ...

CVSS3: 9.9
github
2 месяца назад

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

9.9 Critical

CVSS3