Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97147

Quick assessment

Affected
OpenStack Mistral
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Mistral 23.0.0 及更早版本中,其 v2 API 的多个写入路径存在漏洞。这些路径在解析目标对象时使用了一种查询方式,该查询可能返回属于其他项目的资源,随后对其进行写入操作。已认证的项目成员可利用此漏洞,重写并取消发布其他项目的公开操作定义和环境配置。此外,项目管理员可以创建工作簿,其中嵌入的临时操作或工作流的名称与另一个项目中的资源发生名称冲突,从而导致该资源被转移到调用者所在的项目中,并使得原始拥有者在后续对该资源进行更新时引发服务器错误。只有公开暴露 Mistral API

CVSS 7.2 · High

Affected Version Matrix 4

VendorProduct Version RangeStatus
OpenStack Mistral < 20.1.1 affected
21.0.0< 21.0.1 affected
22.0.0< 22.0.1 affected
23.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97147

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Mistral 0 ~ 20.1.1 -

II. Public POCs for CVE-2026-97147

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97147

请登录查看更多情报信息。

Other References for CVE-2026-97147 (2)

Same Patch Batch · OpenStack · 2026-10-08 · 4 CVEs total

CVE-2026-93858 8.7 HIGH OpenStack Mistral≤23.0.0远程命令执行漏洞
CVE-2026-93860 7.1 HIGH OpenStack Mistral≤23.0.0 API越权致服务中断
CVE-2026-93861 6.0 MEDIUM OpenStack Mistral通过API实现越权访问

IV. Related Vulnerabilities

V. Comments for CVE-2026-97147

No comments yet


Leave a comment