Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93858

Quick assessment

Affected
OpenStack Mistral
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Mistral 23.0.0 及之前版本中, 操作会将用户提供的 值直接传递给 ,而在尝试建立到网关或目标主机的任何 SSH 连接之前,并未进行适当验证。经过认证的项目成员可以通过标准的操作执行 API 提交任意本地命令作为 ;Paramiko 会在执行主机上以执行服务的自有服务账户身份将该命令作为子进程启动,无论后续的 SSH 连接是否成功。只有那些允许使用 操作的 Mistral 部署实例(默认为启用状态)才受此漏洞影响。

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 4

VendorProduct Version RangeStatus
OpenStack Mistral < 20.1.1 affected
21.0.0< 21.0.1 affected
22.0.0< 22.0.1 affected
23.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93858

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Mistral 0 ~ 20.1.1 -

II. Public POCs for CVE-2026-93858

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93858

请登录查看更多情报信息。

Other References for CVE-2026-93858 (2)

Same Patch Batch · OpenStack · 2026-10-08 · 4 CVEs total

CVE-2026-97147 7.2 HIGH OpenStack Mistral 23.0.0越权修改/接管项目资源漏洞
CVE-2026-93860 7.1 HIGH OpenStack Mistral≤23.0.0 API越权致服务中断
CVE-2026-93861 6.0 MEDIUM OpenStack Mistral通过API实现越权访问

IV. Related Vulnerabilities

V. Comments for CVE-2026-93858

No comments yet


Leave a comment