CVE-2026-93860
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.
| CWE | CWE-862 |
| Vendor | openstack |
| Product | mistral |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for openstack mistral
Be the first to know when new unknown vulnerabilities affecting openstack mistral are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OpenStack / Mistral
0 < 20.1.1 21.0.0 < 21.0.1 22.0.0 < 22.0.1 23.0.0