CVE-2026-41283Critical· 9.9▾ MidnightOpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
mistral >= 20.0.0, < 20.1.1mistralmistralUpgrade to a patched release:
mistral 20.1.1