← All CVEs

CVE-2026-41283

critical · 9.9

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

9.9
CVSS
0.7%
EPSS (exploit prob.)
53rd
EPSS percentile
2026-06-04
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-863CWE-749

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-41283