Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross-Project Write Authorization Bypass in OpenStack Mistral API |
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack mistral |
|
| Vendors & Products |
Openstack
Openstack mistral |
Thu, 08 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T17:41:29.934Z
Reserved: 2026-09-24T02:16:02.138Z
Link: CVE-2026-97147
No data.
Status : Deferred
Published: 2026-10-08T18:18:33.583
Modified: 2026-10-08T21:10:41.427
Link: CVE-2026-97147
No data.
OpenCVE Enrichment
Updated: 2026-10-08T21:00:14Z
-
CWE-863
Incorrect Authorization