logo

Critical Policy Bypass Flaw Threatens OpenStack Mistral Workflow Environments

ID: 2a84dac1-7cd4-5e5a-9462-c55b9ccaf78f

STIX ID: report--2a84dac1-7cd4-5e5a-9462-c55b9ccaf78f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Do Son

...
...

### Executive summary The report details a critical zero-day (CVE-2026-41283) in OpenStack Mistral where missing policy enforcement on API endpoints permits authenticated but non-privileged users to create public resources and execute arbitrary code on executor workers, with the additional risk of extracting service credentials; vendor patches are available and administrators are urged to apply them immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.