Critical severity9.9NVD Advisory· Published Jun 4, 2026· Updated Jul 22, 2026
CVE-2026-41283
CVE-2026-41283
Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistralPyPI | >= 20.0.0, < 20.1.1 | 20.1.1 |
Affected products
2Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-9hfw-w3f4-c4p8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41283ghsaADVISORY
- www.openwall.com/lists/oss-security/2026/06/03/14nvdWEB
- access.redhat.com/security/cve/CVE-2026-41283nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/openstack/mistral/tagsnvdWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.jsonnvdWEB
- security.openstack.org/ossa/OSSA-2026-020.htmlnvdWEB
- www.openwall.com/lists/oss-security/2026/06/03/14nvdWEB
News mentions
1- OpenStack: Critical RCE and Multiple Ironic Flaws Disclosed TogetherVypr Intelligence · Jun 4, 2026