VDB
CVE-2026-41283
CVE-2026-41283
PUBLISHED
CVSS 9.9 CRITICAL
Reported by mitre · Published June 4, 2026
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Risk Scores
CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenStack | Mistral | 20.0.0, 21.0.0, 22.0.0 |
| OpenStack | Mistral | 22.0.0, 20.0.0, 21.0.0 |
| PyPI | mistral | 20.0.0, 21.0.0, 22.0.0 |
| Red Hat | Red Hat OpenStack Platform 16.2 | |
| Red Hat | Red Hat OpenStack Platform 16.2 |
Timeline
- Jun 4, 2026 CVE Published
- Jun 5, 2026 EPSS Score
- Jun 7, 2026 Security Advisory
- Jun 9, 2026 Coalition ESS Score
- Jul 22, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-41283 advisory
- https://github.com/advisories/GHSA-9hfw-w3f4-c4p8 advisory
- http://www.openwall.com/lists/oss-security/2026/06/03/14 url
- RHBZ#2484607 issue
- https://access.redhat.com/security/cve/CVE-2026-41283 advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json advisory