VDB

CVE-2026-41283

CVE-2026-41283 PUBLISHED CVSS 9.9 CRITICAL

Reported by mitre · Published June 4, 2026

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
OpenStackMistral20.0.0, 21.0.0, 22.0.0
OpenStackMistral22.0.0, 20.0.0, 21.0.0
PyPImistral20.0.0, 21.0.0, 22.0.0
Red HatRed Hat OpenStack Platform 16.2
Red HatRed Hat OpenStack Platform 16.2

Timeline

  • Jun 4, 2026 CVE Published
  • Jun 5, 2026 EPSS Score
  • Jun 7, 2026 Security Advisory
  • Jun 9, 2026 Coalition ESS Score
  • Jul 22, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›