CVE-2026-93858: CWE-78 OS Command Injection in OpenStack Mistral
Description
In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.
CVSS v4.0
Score 8.7high
Affected software
OpenStack
Mistral
pkg:pypi/openstack/mistralRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenStack Mistral versions through 23.0.0 contain an OS command injection vulnerability (CWE-78) in the std.ssh_proxied action. The action accepts a proxy_command parameter from an authenticated user and passes it directly to paramiko.ProxyCommand() without sanitization. This causes paramiko to execute the supplied command as a subprocess on the executor host under the executor's service account, regardless of whether the SSH connection succeeds. This allows an authenticated project member to run arbitrary local commands on the executor host, potentially leading to privilege abuse or further compromise. The vulnerability affects versions >=0 <20.1.1, >=21.0.0 <21.0.1, >=22.0.0 <22.0.1, and =23.0.0. The default configuration enabling std.ssh_proxied is affected.
Potential Impact
An authenticated project member can execute arbitrary local commands on the executor host with the executor's service account privileges. This can lead to unauthorized command execution, potential privilege escalation, and compromise of the host running Mistral. The vulnerability does not require user interaction beyond authentication and affects the default configuration of Mistral.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the std.ssh_proxied action if possible to prevent exploitation. Restrict project member permissions to limit exposure. Monitor for unusual command execution activity on executor hosts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-09-18T19:09:49.629Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac7d8742cdf04f6562d26c0
Added to database: 10/08/2026, 17:52:52 UTC
Last enriched: 10/08/2026, 18:03:25 UTC
Last updated: 10/08/2026, 21:45:56 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.