PYSEC-2026-3486

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/mistral/PYSEC-2026-3486.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3486
Aliases
Published
2026-07-23T11:41:38Z
Modified
2026-07-23T15:00:15Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
Details

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

References

Affected packages

PyPI / mistral

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
20.0.0
Fixed
20.1.1

Affected versions

20.*
20.0.0
20.1.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/mistral/PYSEC-2026-3486.yaml"

PyPI / mistral

Package

Affected ranges

Affected versions

21.*
21.0.0
22.*
22.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/mistral/PYSEC-2026-3486.yaml"