OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral

Date:

October 08, 2026

CVE:

CVE-2026-93858, CVE-2026-93860, CVE-2026-93861, CVE-2026-97147

Affects

  • Mistral: <20.1.1, ==21.0.0, ==22.0.0, ==23.0.0

Description

Arnaud Morin from OVHcloud reported that several of Mistral’s v2 API write paths resolve the target object with a query that can return another project’s resource, then write to it (CVE-2026-97147). An authenticated project member can use this to rewrite and un-publish another project’s public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller’s project and causes the original owner’s subsequent updates of it to fail with server errors. All deployments exposing the Mistral API are affected.

Chen YuXiang from the Institute of Computing Technology, Chinese Academy of Sciences reported that Mistral’s workflow membership API lets a project that has accepted a share of another project’s private workflow create a further membership naming a third project (CVE-2026-93861). The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, so the owner can neither see nor delete it. The third project can accept this membership it was never actually granted by the owner, then read and execute the owner’s private workflow; only the accepting (not the owning) project can later revoke that access.

Chen YuXiang also reported a vulnerability in Mistral’s ssh_proxied action provider (CVE-2026-93858). By supplying a specially-crafted action payload, an unprivileged authenticated user may override paramiko’s proxy_command resulting in execution of arbitrary code on the executor host operating system. Only Mistral deployments allowing the std.ssh_proxied action provider (the default) are affected.

Chen YuXiang further reported a vulnerability in Mistral’s maintenance API method (CVE-2026-93860). By calling the maintenance API method, an unprivileged authenticated user may pause processing for creation of new objects for all tenant projects resulting in a temporary denial of service. All Mistral deployments are affected.

Patches

Credits

  • Arnaud Morin from OVHcloud (CVE-2026-97147)

  • Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences (CVE-2026-93858, CVE-2026-93860, CVE-2026-93861)

References