CVE-2026-93860

CVE-2026-93860CVE-2026-93860

Description

In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it.

Scoring

Last modified2026-10-08
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.