Description
In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.
Published: 2026-10-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Misassigned Workflow Membership Enables Unauthorized Access to Private Workflows in OpenStack Mistral openstack-mistral: mistral: workflow membership sub-delegation allows unauthorized access grant to private workflows
Weaknesses CWE-862
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Thu, 08 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack mistral
Vendors & Products Openstack
Openstack mistral

Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Title Misassigned Workflow Membership Enables Unauthorized Access to Private Workflows in OpenStack Mistral

Thu, 08 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openstack Mistral
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-08T17:38:43.892Z

Reserved: 2026-09-18T19:15:59.203Z

Link: CVE-2026-93861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T18:18:31.153

Modified: 2026-10-08T21:10:41.427

Link: CVE-2026-93861

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-08T19:17:47Z

Links: CVE-2026-93861 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T03:15:15Z

Weaknesses