CVE-2026-93861
Received Received - Intake

Membership Privilege Escalation in OpenStack Mistral

Vulnerability report for CVE-2026-93861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
OpenStack Mistral 0
OpenStack Mistral 21.0.0
OpenStack Mistral 22.0.0
OpenStack Mistral 23.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenStack Mistral allows a project that has accepted a share of another project's private workflow to create a membership for a third project without the original owner's permission. The membership row is incorrectly assigned to the accepting project instead of the owner, preventing the owner from seeing or deleting it. The third project can then accept this unauthorized membership and access the owner's private workflow.

Impact Analysis

If you are a user of OpenStack Mistral, an attacker could gain unauthorized access to your private workflows by exploiting this flaw. This could lead to data breaches, unauthorized execution of workflows, or loss of control over shared resources. Only projects with accepted memberships can revoke access, not the original workflow owner.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR or HIPAA. Unauthorized access to workflows may result in data breaches, which could lead to legal penalties, loss of trust, and failure to meet regulatory standards.

Mitigation Strategies

Upgrade OpenStack Mistral to version 20.1.1 or later to address the vulnerability. Review all workflow memberships in the system to identify unauthorized derived memberships created by Project B for Project C. Remove any unauthorized memberships and restrict project permissions to prevent similar issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93861. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart