Skip to main content

CVE-2026-93858: CWE-78 OS Command Injection in OpenStack Mistral

0
High
Published: 10/08/2026 (10/08/2026, 18:32:30 UTC)
Source: CVE Database V5
Vendor/Project: OpenStack
Product: Mistral

Description

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
Low
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N

Affected software

OpenStack

Mistral

Affected versions
>=0 <20.1.1>=21.0.0 <21.0.1>=22.0.0 <22.0.1=23.0.0
openstack/mistral
pkg:pypi/openstack/mistral
Affected versions
>=0 <20.1.1>=21.0.0 <21.0.1>=22.0.0 <22.0.1=23.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 18:03:25 UTC

Technical Analysis

OpenStack Mistral versions through 23.0.0 contain an OS command injection vulnerability (CWE-78) in the std.ssh_proxied action. The action accepts a proxy_command parameter from an authenticated user and passes it directly to paramiko.ProxyCommand() without sanitization. This causes paramiko to execute the supplied command as a subprocess on the executor host under the executor's service account, regardless of whether the SSH connection succeeds. This allows an authenticated project member to run arbitrary local commands on the executor host, potentially leading to privilege abuse or further compromise. The vulnerability affects versions >=0 <20.1.1, >=21.0.0 <21.0.1, >=22.0.0 <22.0.1, and =23.0.0. The default configuration enabling std.ssh_proxied is affected.

Potential Impact

An authenticated project member can execute arbitrary local commands on the executor host with the executor's service account privileges. This can lead to unauthorized command execution, potential privilege escalation, and compromise of the host running Mistral. The vulnerability does not require user interaction beyond authentication and affects the default configuration of Mistral.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider disabling the std.ssh_proxied action if possible to prevent exploitation. Restrict project member permissions to limit exposure. Monitor for unusual command execution activity on executor hosts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
mitre
Date Reserved
2026-09-18T19:09:49.629Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac7d8742cdf04f6562d26c0

Added to database: 10/08/2026, 17:52:52 UTC

Last enriched: 10/08/2026, 18:03:25 UTC

Last updated: 10/08/2026, 21:45:56 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses