OpenStack Mistral <=23.0.0: Membership API Priv Escal via Wrong Project ID
CVE-2026-93861 Published on October 8, 2026
In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.
Vulnerability Analysis
CVE-2026-93861 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-93861 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
OpenStack Mistral:- Before 20.1.1 is affected.
- Version 21.0.0 and below 21.0.1 is affected.
- Version 22.0.0 and below 22.0.1 is affected.
- Version 23.0.0 is affected.