OpenStack Mistral flaws allow cross-project writes and host RCE
Four CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
OpenStack has issued a security advisory for four authorization and privilege flaws in Mistral, its workflow-as-a-service component. The bugs let authenticated users tamper with other projects' resources and, in one case, execute arbitrary code on the executor host. Affected lines include Mistral before 20.1.1 and the 21.0.0, 22.0.0, and 23.0.0 releases. Every deployment that exposes the Mistral API is in scope for the cross-project issues.
Arnaud Morin of OVHcloud reported that several v2 API write paths resolve a target object in a way that can return another project's resource, then write to it (CVE-2026-97147). An authenticated project member can rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with another project's resource, which moves that resource into the caller's project so the original owner's later updates fail with server errors.
Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences, reported that the workflow membership API lets a project that has already accepted a share of another project's private workflow create a further membership for a third project (CVE-2026-93861). The new membership is stored under the accepting project rather than the original owner, so the owner cannot see or delete it. The third project can accept access it was never granted by the owner, then read and execute the private workflow; only the accepting project can revoke that access afterward.
The same researcher also found that Mistral's default ssh_proxied action provider is unsafe (CVE-2026-93858). A specially crafted action payload can override Paramiko's proxy command and run arbitrary code on the executor host operating system. Only deployments that leave that provider enabled are affected. The advisory also tracks CVE-2026-93860 among the four issues covered under OSSA-2026-044.