« Volver al listado

CVE-2026-93861

Estado: AplazadaMedia (6)—

En OpenStack Mistral hasta la 23.0.0, la API de pertenencia a flujos de trabajo permite que un proyecto que ha aceptado la compartición de un flujo de trabajo privado de otro proyecto cree una pertenencia adicional que designe a un tercer proyecto. La nueva fila de pertenencia se crea con su project_id establecido por defecto en el proyecto que acepta en lugar del propietario original del flujo de trabajo, por lo que el propietario no puede verla ni eliminarla. El tercer proyecto puede aceptar esta pertenencia (que en realidad no le ha concedido el propietario) y, a continuación, leer y ejecutar el flujo de trabajo privado del propietario; solo el proyecto que acepta (no el propietario) puede revocar posteriormente ese acceso.

Traducción automática del texto original de NVD (en inglés).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS: N/AC:L/PR:L (red con privilegios), implica T1210. Acceso no autorizado a flujos privados (T1078) y lectura de datos de workflow (T1005); vulnerabilidad de autorización (CWE-863) en API de membresía.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93861",
  "cveTags": [],
  "metrics": {
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "repo": "https://opendev.org/openstack/mistral",
          "vendor": "OpenStack",
          "product": "Mistral",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "20.1.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "21.0.0",
              "lessThan": "21.0.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "22.0.0",
              "lessThan": "22.0.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.0.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-08T18:18:31.153",
  "references": [
    {
      "url": "https://launchpad.net/bugs/2161277",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.openstack.org/ossa/OSSA-2026-044.html",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access."
    }
  ],
  "lastModified": "2026-10-08T21:10:41.427",
  "sourceIdentifier": "cve@mitre.org"
}