CVE-2026-5412
- EPSS 0.01%
- Veröffentlicht 10.04.2026 12:22:05
- Zuletzt bearbeitet 30.04.2026 15:18:26
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileg...
CVE-2026-5774
- EPSS 0.01%
- Veröffentlicht 10.04.2026 12:10:55
- Zuletzt bearbeitet 22.04.2026 20:46:45
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
CVE-2025-68153
- EPSS 0.01%
- Veröffentlicht 03.04.2026 15:28:06
- Zuletzt bearbeitet 21.04.2026 01:24:01
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticate...
CVE-2025-68152
- EPSS 0.01%
- Veröffentlicht 03.04.2026 15:25:56
- Zuletzt bearbeitet 21.04.2026 01:18:39
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible t...
- EPSS 0.04%
- Veröffentlicht 01.04.2026 08:09:17
- Zuletzt bearbeitet 02.04.2026 20:24:48
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's data...
CVE-2026-32694
- EPSS 0.06%
- Veröffentlicht 18.03.2026 12:55:42
- Zuletzt bearbeitet 19.03.2026 15:05:34
In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which can request ...
CVE-2026-32693
- EPSS 0.07%
- Veröffentlicht 18.03.2026 12:47:02
- Zuletzt bearbeitet 19.03.2026 15:17:00
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs ...
CVE-2026-32692
- EPSS 0.03%
- Veröffentlicht 18.03.2026 12:35:29
- Zuletzt bearbeitet 19.03.2026 15:23:26
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker ...
CVE-2026-32691
- EPSS 0.01%
- Veröffentlicht 18.03.2026 12:28:11
- Zuletzt bearbeitet 19.03.2026 15:34:39
A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revisi...
CVE-2026-1237
- EPSS 0.01%
- Veröffentlicht 28.01.2026 15:01:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabl...