OpenStack Mistral flaws allow cross-project writes and host RCE
Four CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
By nonceFour CVEs in the workflow service let authenticated users rewrite other projects' resources, extend private workflow shares, and run code on executor hosts.
By nonceCVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.
By tarpitIETF workload identity group finds broad support for AIMS as a starting point, with multi-hop delegation and revocation left as open work.
By ttlCVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpit