Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | openstack-mistral: mistral: Unauthenticated-project user can trigger global maintenance mode causing cross-tenant denial of service | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 08 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack mistral |
|
| Vendors & Products |
Openstack
Openstack mistral |
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T17:35:43.653Z
Reserved: 2026-09-18T19:12:29.649Z
Link: CVE-2026-93860
No data.
Status : Deferred
Published: 2026-10-08T18:18:30.993
Modified: 2026-10-08T21:10:41.427
Link: CVE-2026-93860
OpenCVE Enrichment
Updated: 2026-10-08T19:15:20Z