Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:HCanonical Juju
APPCanonical< 2.9.513.1.0 – 3.1.10 (excl.)3.2.0 – 3.2.43.3 – 3.3.7 (excl.)3.4 – 3.4.6 (excl.)3.5.0 – 3.5.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
Related vulnerabilities
CVE-2026-5412CRITICAL9.9PL ✓same product
Canonical Juju — nieuprawniony dostęp do poświadczeń chmury przez Controller facade
CVE-2026-4370CRITICAL10.0PL ✓same product
Canonical Juju: brak uwierzytelnienia TLS w klastrze Dqlite umożliwia przejęcie bazy danych
CVE-2017-9232CRITICAL9.8PL ✓same product
Privilege escalation w Juju przez niezabezpieczony UNIX domain socket
CVE-2025-68153HIGH7.1same product
Juju is an open source application orchestration engine that enables any application operation on any infrastr...
CVE-2026-32693HIGH8.8same product
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correct...