#1150346 CVE-2026-93858, CVE-2026-93860, CVE-2026-93861, CVE-2026-97147, OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral

Package:
src:mistral
Source:
src:mistral
Submitter:
Thomas Goirand
Date:
2026-10-09 11:13:03 UTC
Severity:
normal
Tags:
#1150346#5
Date:
2026-10-08 19:41:16 UTC
From:
To:
As per upstream announce here:
https://security.openstack.org/ossa/OSSA-2026-044.html

OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral

Date: October 08, 2026
CVE: CVE-2026-93858,
     CVE-2026-93860,
     CVE-2026-93861,
     CVE-2026-97147

Affects
~~~~~~~
- Mistral: <20.1.1, ==21.0.0, ==22.0.0, ==23.0.0

Description
~~~~~~~~~~~
Arnaud Morin from OVHcloud reported that several of Mistral's v2 API write
paths resolve the target object with a query that can return another
project's resource, then write to it (CVE-2026-97147). An authenticated
project member can use this to rewrite and un-publish another project's
public action definitions and environments. A project administrator can
create a workbook whose embedded ad-hoc action or workflow name collides
with a resource of another project, which moves that resource into the
caller's project and causes the original owner's subsequent updates of it
to fail with server errors. All deployments exposing the Mistral API are
affected.

Chen YuXiang from the Institute of Computing Technology, Chinese Academy of
Sciences reported that Mistral's workflow membership API lets a project that
has accepted a share of another project's private workflow create a further
membership naming a third project (CVE-2026-93861). The new membership row
is created with its project_id defaulted to the accepting project rather
than the original workflow owner, so the owner can neither see nor delete
it. The third project can accept this membership it was never actually
granted by the owner, then read and execute the owner's private workflow;
only the accepting (not the owning) project can later revoke that access.

Chen YuXiang also reported a vulnerability in Mistral's ssh_proxied action
provider (CVE-2026-93858). By supplying a specially-crafted action payload,
an unprivileged authenticated user may override paramiko's proxy_command
resulting in execution of arbitrary code on the executor host operating
system. Only Mistral deployments allowing the std.ssh_proxied action
provider (the default) are affected.

Chen YuXiang further reported a vulnerability in Mistral's maintenance API
method (CVE-2026-93860). By calling the maintenance API method, an
unprivileged authenticated user may pause processing for creation of new
objects for all tenant projects resulting in a temporary denial of service.
All Mistral deployments are affected.

Patches
~~~~~~~
- https://review.opendev.org/1009502 (2025.1/epoxy)
- https://review.opendev.org/1009503 (2025.1/epoxy)
- https://review.opendev.org/1009504 (2025.1/epoxy)
- https://review.opendev.org/1009505 (2025.1/epoxy)
- https://review.opendev.org/1009506 (2025.1/epoxy)
- https://review.opendev.org/1009507 (2025.1/epoxy)
- https://review.opendev.org/1009508 (2025.1/epoxy)
- https://review.opendev.org/1009509 (2025.1/epoxy)
- https://review.opendev.org/1009493 (2025.2/flamingo)
- https://review.opendev.org/1009494 (2025.2/flamingo)
- https://review.opendev.org/1009495 (2025.2/flamingo)
- https://review.opendev.org/1009496 (2025.2/flamingo)
- https://review.opendev.org/1009497 (2025.2/flamingo)
- https://review.opendev.org/1009498 (2025.2/flamingo)
- https://review.opendev.org/1009499 (2025.2/flamingo)
- https://review.opendev.org/1009500 (2025.2/flamingo)
- https://review.opendev.org/1009484 (2026.1/gazpacho)
- https://review.opendev.org/1009485 (2026.1/gazpacho)
- https://review.opendev.org/1009486 (2026.1/gazpacho)
- https://review.opendev.org/1009487 (2026.1/gazpacho)
- https://review.opendev.org/1009488 (2026.1/gazpacho)
- https://review.opendev.org/1009489 (2026.1/gazpacho)
- https://review.opendev.org/1009490 (2026.1/gazpacho)
- https://review.opendev.org/1009491 (2026.1/gazpacho)
- https://review.opendev.org/1009476 (2026.2/hibiscus)
- https://review.opendev.org/1009477 (2026.2/hibiscus)
- https://review.opendev.org/1009478 (2026.2/hibiscus)
- https://review.opendev.org/1009479 (2026.2/hibiscus)
- https://review.opendev.org/1009480 (2026.2/hibiscus)
- https://review.opendev.org/1009481 (2026.2/hibiscus)
- https://review.opendev.org/1009482 (2026.2/hibiscus)
- https://review.opendev.org/1009483 (2026.2/hibiscus)
- https://review.opendev.org/1009468 (2027.1/indri (development))
- https://review.opendev.org/1009469 (2027.1/indri (development))
- https://review.opendev.org/1009470 (2027.1/indri (development))
- https://review.opendev.org/1009471 (2027.1/indri (development))
- https://review.opendev.org/1009472 (2027.1/indri (development))
- https://review.opendev.org/1009473 (2027.1/indri (development))
- https://review.opendev.org/1009474 (2027.1/indri (development))
- https://review.opendev.org/1009475 (2027.1/indri (development))

Credits
~~~~~~~
- Arnaud Morin from OVHcloud (CVE-2026-97147)
- Chen YuXiang from Institute of Computing Technology, Chinese Academy of
Sciences (CVE-2026-93858, CVE-2026-93860, CVE-2026-93861)


References
~~~~~~~~~~
- https://launchpad.net/bugs/2160267 (CVE-2026-97147)
- https://launchpad.net/bugs/2161277 (CVE-2026-93861)
- https://launchpad.net/bugs/2162100 (CVE-2026-93858)
- https://launchpad.net/bugs/2162789 (CVE-2026-93860)
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93858
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93860
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-93861
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-97147

#1150346#8
Date:
2026-10-08 21:50:05 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/e016a4b576cd3700a1bfd9cb7e3ff8a6f96e0b3e
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * OSSN-0098: Mistral workflow execution context exposes Keystone auth token.
    Applied upstream patch: "Strip sensitive info from workflow execution
    context" (Closes: #1138849).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#13
Date:
2026-10-08 21:50:17 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/127804a9012f6b9a68785c499672760f14b388f1
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#16
Date:
2026-10-08 21:50:36 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/f6c8074a02fc811bc1e143f7ece425c16896fa1c
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#19
Date:
2026-10-08 21:50:47 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/9b6c3f3133dc76bad42d9164621041a787c985e8
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#22
Date:
2026-10-08 21:51:04 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/0c7a2938e94e110237ec583754a98814156135aa
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#25
Date:
2026-10-08 21:51:27 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/706c260e136c95be8bf07e5d96def3ed6c247f02
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#28
Date:
2026-10-08 21:52:06 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/2ffda39a6f9444c7a8c4c81eeb3b17969a0ed6d9
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#31
Date:
2026-10-08 21:52:30 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/ed3ee5d177acbb8b7427ed6e89e786635b167c49
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#34
Date:
2026-10-08 21:52:47 UTC
From:
To:
Hello,

Bug #1150346 in mistral reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/mistral/-/commit/cee039ca325b06df1a67d0aae5f6921d06eae654
------------------------------------------------------------------------
* OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
    with the details as per below (Closes: #1150346).
  * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
    object with a query that can return another project's resource, then write
    to it (CVE-2026-97147). An authenticated project member can use this to
    rewrite and un-publish another project's public action definitions and
    environments. A project administrator can create a workbook whose embedded
    ad-hoc action or workflow name collides with a resource of another project,
    which moves that resource into the caller's project and causes the original
    owner's subsequent updates of it to fail with server errors. All
    deployments exposing the Mistral API are affected. Applied upstream
    patches: "Fix create-or-update of definitions hijacking other projects'
    rows", "Enforce access control when updating action definitions", "Enforce
    access control when updating workbooks and environments", "Resolve
    own-project object when updating code sources / dynamic actions", "Resolve
    own-project cron trigger in create_or_update_cron_trigger":
    - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
    - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
    - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
    - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
    Added my own patch to fix broken unit test:
    - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
  * CVE-2026-93861: Mistral's workflow membership API lets a project that has
    accepted a share of another project's private workflow create a further
    membership naming a third project (CVE-2026-93861). The new membership row
    is created with its project_id defaulted to the accepting project rather
    than the original workflow owner, so the owner can neither see nor delete
    it. The third project can accept this membership it was never actually
    granted by the owner, then read and execute the owner's private workflow;
    only the accepting (not the owning) project can later revoke that access.
    Applied upstream patch: "Only allow the owner of a resource to share it":
    - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
  * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
    supplying a specially-crafted action payload, an unprivileged authenticated
    user may override paramiko's proxy_command resulting in execution of
    arbitrary code on the executor host operating system. Only Mistral
    deployments allowing the std.ssh_proxied action provider (the default) are
    affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
    proxy_command":
    - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
  * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
    calling the maintenance API method, an unprivileged authenticated user may
    pause processing for creation of new objects for all tenant projects
    resulting in a temporary denial of service. All Mistral deployments are
    affected. Applied upstream patch: "Restrict the maintenance endpoint to
    admins":
    - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150346

#1150346#41
Date:
2026-10-09 11:12:20 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
mistral, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150346@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated mistral package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 01 Oct 2026 21:27:47 +0200
Source: mistral
Architecture: source
Version: 23.0.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1150346
Changes:
 mistral (23.0.0-2) unstable; urgency=high
 .
   * OSSA-2026-044: Four authorization and privilege vulnerabilities in Mistral,
     with the details as per below (Closes: #1150346).
   * CVE-2026-97147: several of Mistral's v2 API write paths resolve the target
     object with a query that can return another project's resource, then write
     to it (CVE-2026-97147). An authenticated project member can use this to
     rewrite and un-publish another project's public action definitions and
     environments. A project administrator can create a workbook whose embedded
     ad-hoc action or workflow name collides with a resource of another project,
     which moves that resource into the caller's project and causes the original
     owner's subsequent updates of it to fail with server errors. All
     deployments exposing the Mistral API are affected. Applied upstream
     patches: "Fix create-or-update of definitions hijacking other projects'
     rows", "Enforce access control when updating action definitions", "Enforce
     access control when updating workbooks and environments", "Resolve
     own-project object when updating code sources / dynamic actions", "Resolve
     own-project cron trigger in create_or_update_cron_trigger":
     - CVE-2026-97147_Fix_create-or-update_of_definitions_hijacking_oth....patch
     - CVE-2026-97147_Enforce_access_control_when_updating_action_defin....patch
     - CVE-2026-97147_Enforce_access_control_when_updating_workbooks_an....patch
     - CVE-2026-97147_Resolve_own-project_object_when_updating_code_sou....patch
     - CVE-2026-97147_Resolve_own-project_cron_trigger_in_create_or_upd....patch
     Added my own patch to fix broken unit test:
     - CVE-2026-97147_Resolve_own-project_object_Fix-test-DB-cleanup-fo....patch
   * CVE-2026-93861: Mistral's workflow membership API lets a project that has
     accepted a share of another project's private workflow create a further
     membership naming a third project (CVE-2026-93861). The new membership row
     is created with its project_id defaulted to the accepting project rather
     than the original workflow owner, so the owner can neither see nor delete
     it. The third project can accept this membership it was never actually
     granted by the owner, then read and execute the owner's private workflow;
     only the accepting (not the owning) project can later revoke that access.
     Applied upstream patch: "Only allow the owner of a resource to share it":
     - CVE-2026-93861_Only_allow_the_owner_of_a_resource_to_share_it.patch
   * CVE-2026-93858: Mistral's ssh_proxied action provider (CVE-2026-93858). By
     supplying a specially-crafted action payload, an unprivileged authenticated
     user may override paramiko's proxy_command resulting in execution of
     arbitrary code on the executor host operating system. Only Mistral
     deployments allowing the std.ssh_proxied action provider (the default) are
     affected. Applied upstream patch: "Fix RCE via std.ssh_proxied
     proxy_command":
     - CVE-2026-93858_Fix_RCE_via_std.ssh_proxied_proxy_command.patch
   * CVE-2026-93860: vulnerability in Mistral's maintenance API method. By
     calling the maintenance API method, an unprivileged authenticated user may
     pause processing for creation of new objects for all tenant projects
     resulting in a temporary denial of service. All Mistral deployments are
     affected. Applied upstream patch: "Restrict the maintenance endpoint to
     admins":
     - CVE-2026-93860_Restrict_the_maintenance_endpoint_to_admins.patch
Checksums-Sha1:
 0b19dcc384d032bb387140a4bd6ece24f6e50a8e 3428 mistral_23.0.0-2.dsc
 2e459c56a8706e58700a9af216bf4b9f8ea86c62 24992 mistral_23.0.0-2.debian.tar.xz
 58a9600cf145dc071b67e896b5f9fc962bc3b3b6 16922 mistral_23.0.0-2_amd64.buildinfo
Checksums-Sha256:
 2f78033375e6ffb9555a9c34adf7c5c552ab38f28c49ead7236c914e9272f5b1 3428 mistral_23.0.0-2.dsc
 a68bea9089d821dfed4d5bfa1bfc7b63c71a37bbe2275cc5b8fdb2b41efb82cf 24992 mistral_23.0.0-2.debian.tar.xz
 da3ab03ed58c7836342aeed4d2ee2ae80018530e95fde1696432132388fb98ff 16922 mistral_23.0.0-2_amd64.buildinfo
Files:
 16cb58f46f882a665ae8d8f45733b4e1 3428 net optional mistral_23.0.0-2.dsc
 98e03977662851237a754f8e70dfdbae 24992 net optional mistral_23.0.0-2.debian.tar.xz
 dde25bf46f641ac5511c6a4e1e4cf67a 16922 net optional mistral_23.0.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmrIxMAACgkQ1BatFaxr
Q/6qiw/5AaAmaFT+UsCWxQAzwTrwArsNeFIGFDY5E+gNqukZfOr0p/NjNVy6hrWJ
KWBthF1A5X0dGF3Xjj1kFJflXhZf+qCWR8qnh+MTqL4hi0/BnOCbWVCL6Q90Shrs
vRQdfmmWAshTp4Q+GZSBeomgBhGP/T9euTL5zV/VMGG/BBVvjEnTRwVkyCY2SHWc
FxwI9d0Fl/1vR2p0HJ2GP2tj6Xs0HaQN2Uc8QHt2R7CzV17SOHRZNNfi/EkX5WsU
dolRz2P9jEa1xnNPLfIr9qKFs/FDvlCAAvt4qf80R2dJ1//sppvSRuY5FaftPmIZ
Mwkbq+xbSoB9N47vbaMEPjRi0WeKf/p2zjTPS5RUXpZebu62WRaoB//UOf70WWWS
ZrTnP1eHNPgbQlh59wmGxAxAFXmmwaKO5qrMukZff7nSrI3UhZSEEB6vM8Ns+Dyp
XyuomyMEf5BbxxNGM7XNeR5kkkSE/9RlQ0RFOVOampPxvXw3ev3S5PAJZcAkTbQs
puHNZGR01CX1f5MLl6CN+xvciDc9K/0BCpCPc23pjROxGL9Kkb03Qxg2b/jAI6fZ
7T5wrJWueB8zGH7diKgvfVqSILjP9BxG8Z03cWY6qGZIPjW/S5a1e1lfbjH7xbMh
/6jNR72q56wD3qiaXP+fMj9YzvfL22V3JAYT1ny/xLEY9rZV2SM=
=fLeX
-----END PGP SIGNATURE-----