{"data":{"id":"8f279560-36e9-43ca-b87e-822be72d9217","title":"CVE-2026-93861: In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another…","summary":"In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that accepted a share of another project's private workflow create a further membership naming a third project. The new membership row defaults its project_id to the accepting project rather than the workflow owner, so the owner cannot see or delete it. The third project can accept it and then read and execute the owner's private workflow.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93861","publishedAt":"2026-10-08T18:18:31.153Z","cveId":"CVE-2026-93861","cweIds":["CWE-863"],"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["OpenStack Mistral"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"OpenStack Mistral workflow API lets shared projects grant unauthorized access","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00258,"epssCheckedAt":"2026-10-10T06:42:02.347Z","kevDateAdded":null,"advisoryAliases":["GHSA-p254-mh9p-hpfm"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:34.533Z","patchAvailable":null,"disclosureDate":"2026-10-08T18:18:31.153Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.6,"researchCategory":null,"atlasIds":null}}