CVE-2026-93861

Source
https://cve.org/CVERecord?id=CVE-2026-93861
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93861.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93861
Downstream
Published
2026-10-08T17:38:43Z
Modified
2026-10-10T02:47:25Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93861.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "20.1.1"
                },
                {
                    "introduced": "21.0.0"
                },
                {
                    "fixed": "21.0.1"
                },
                {
                    "introduced": "22.0.0"
                },
                {
                    "fixed": "22.0.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / opendev.org/openstack/mistral

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/mistral
Events
Introduced
a28388efe2dab9d20e444fa6322cdc87372bbd41
Last Affected
a28388efe2dab9d20e444fa6322cdc87372bbd41
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "23.0.0"
        },
        {
            "last_affected": "23.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

23.*
23.0.0
23.0.0.0rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93861.json"