Skip to content
MediumVulnerability

CVE-2026-93861: In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another…

Identifier
CVE-2026-93861
Published
Record updated
View JSON

Summary

In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that accepted a share of another project's private workflow create a further membership naming a third project. The new membership row defaults its project_id to the accepting project rather than the workflow owner, so the owner cannot see or delete it. The third project can accept it and then read and execute the owner's private workflow.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.