CVE-2026-41283
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://www.openwall.com/lists/oss-security/2026/06/03/14, https://github.com/openstack/mistral/tags, https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json, https://security.openstack.org/ossa/OSSA-2026-020.html, https://www.openwall.com/lists/oss-security/2026/06/03/14, https://access.redhat.com/security/cve/CVE-2026-41283, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41283.json, https://nvd.nist.gov/vuln/detail/CVE-2026-41283, https://bugzilla.redhat.com/show_bug.cgi?id=2484607