Bug 2544709 (CVE-2026-97147) - CVE-2026-97147 openstack-mistral: mistral: Cross-project resource tampering via missing ownership check in action definition and environment update paths
Summary: CVE-2026-97147 openstack-mistral: mistral: Cross-project resource tampering v...
Keywords:
Status: NEW
Alias: CVE-2026-97147
Deadline: 2026-10-08
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-01 18:55 UTC by Robb Gatica
Modified: 2026-10-08 19:19 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Robb Gatica 2026-10-01 18:55:49 UTC
A flaw was found in OpenStack Mistral. Several of Mistral's v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can exploit this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, moving that resource into the caller's project and causing the original owner's subsequent updates to fail with server errors.

All deployments exposing the Mistral API are affected.

Affected versions: <20.1.1, ==21.0.0, ==22.0.0, ==23.0.0

Reference: https://launchpad.net/bugs/2160267


Note You need to log in before you can comment on or make changes to this bug.