CVE-2026-97147
Received Received - Intake

OpenStack Mistral Project Resource Rewrite Vulnerability

Vulnerability report for CVE-2026-97147, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
OpenStack Mistral 0
OpenStack Mistral 21.0.0
OpenStack Mistral 22.0.0
OpenStack Mistral 23.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenStack Mistral through 23.0.0 allows authenticated project members to manipulate API write paths. By querying and writing to resources outside their project, they can rewrite or unpublish another project's public action definitions and environments. A project admin can also create workbooks with conflicting names to move another project's resources into their own, causing errors for the original owner.

Impact Analysis

If you use OpenStack Mistral with exposed API, an attacker with project access could alter your public workflows or environments, disrupting your operations. Project admins may face resource conflicts leading to server errors, affecting workflow execution and management.

Mitigation Strategies

Upgrade OpenStack Mistral to a version beyond 23.0.0 to address the vulnerability. Ensure the Mistral API is not exposed to untrusted networks. Review and restrict project member permissions to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97147. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart