PatchSiren cyber security CVE debrief
CVE-2026-93858 OpenStack CVE debrief
CVE-2026-93858 is a vulnerability in OpenStack Mistral that allows an authenticated project member to execute arbitrary local commands on the executor host. The vulnerability exists in the std.ssh_proxied action, which passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() without proper validation. This can lead to command injection and execution of arbitrary commands on the executor host.
- Vendor
- OpenStack
- Product
- Mistral
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
OpenStack Mistral administrators and users who permit the std.ssh_proxied action in their deployments should assess their exposure and take steps to prevent exploitation. This includes reviewing and restricting the use of the std.ssh_proxied action, updating OpenStack Mistral to a version that fixes the vulnerability, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should be aware of the potential for
Why it matters
CVE-2026-93858 is a high-severity vulnerability in OpenStack Mistral that allows authenticated project members to execute arbitrary local commands on the executor host. The vulnerability exists in the std.ssh_proxied action and can be exploited using the standard action-execution API. OpenStack Mistral administrators and users who permit this action should assess their exposure and take steps to prevent exploitation.
- Authenticated project members can execute arbitrary local commands on the executor host.
- Command injection can lead to privilege escalation and unauthorized access.
- The vulnerability can be exploited using the standard action-execution API.
- Verification of affected versions and remediation efforts are necessary.
Technical summary
The std.ssh_proxied action in OpenStack Mistral passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() without validation, allowing authenticated project members to execute arbitrary local commands on the executor host. This vulnerability exists in OpenStack Mistral versions 20.1.1, 21.0.1, 22.0.1, and 23.0.0, and can be exploited using the standard action-execution API. The std.ssh_proxied action is enabled by default, making deployments that permit this action vulnerable. Affected OpenStack Mistral administrators and users should assess their exposure and take steps to prevent exploitation.
Defensive priority
High
Recommended defensive actions
- Review and restrict the use of the std.ssh_proxied action in OpenStack Mistral deployments.
- Update OpenStack Mistral to a version that fixes the vulnerability, if available.
- Monitor for suspicious activity and implement compensating controls to prevent exploitation.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is confirmed to exist in OpenStack Mistral versions 20.1.1, 21.0.1, 22.0.1, and 23.0.0. The std.ssh_proxied action is enabled by default, making deployments that permit this action vulnerable.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93858 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93858
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93858 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93858
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-93858
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93858.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://launchpad.net/bugs/2162100
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://security.openstack.org/ossa/OSSA-2026-044.html
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.