OpenStack Mistral <=23.0.0: /v2/maintenance API Policy Bypass
CVE-2026-93860 Published on October 8, 2026
In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.
Vulnerability Analysis
CVE-2026-93860 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-93860. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-93860 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
OpenStack Mistral:- Before 20.1.1 is affected.
- Version 21.0.0 and below 21.0.1 is affected.
- Version 22.0.0 and below 22.0.1 is affected.
- Version 23.0.0 is affected.