CVE-2026-41283

critical EU-CRITICAL
EUVD alias: EUVD-2026-34201
Published 2026-06-04 Β· Modified 2026-06-04
CVSS v3
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
9.9

Description

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

Predictions

Exploit likelihood
98%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2026-41283 NameCVE-2026-41283 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus mistral (PTS)bullseye11.0.0-2vulnerable bookworm15.0.0-1vulnerable…

CVE-2026-41283

NameCVE-2026-41283
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mistral (PTS)bullseye11.0.0-2vulnerable
bookworm15.0.0-1vulnerable
trixie20.0.0-2vulnerable
forky, sid22.0.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mistralsource(unstable)(unfixed)

Notes

https://www.openwall.com/lists/oss-security/2026/06/03/14
https://launchpad.net/bugs/2147178

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.openwall.com/lists/oss-security/2026/06/03/14https://launchpad.net/bugs/2147178

OS impact

debian Debian Affected 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Affected β€”
forky Affected β€”
bullseye Affected β€”
bookworm Affected β€”

References

CWEs

CWE-863

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.