HIGH🇵🇱 Wersja polska

CVE-2025-68153

CVSS 7.1v4.0pub. 2026-04-03upd. 2026-07-24

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju controller can modify the resources of an application within the entire controller. This issue has been patched in versions 2.9.56 and 3.6.19.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Canonical Juju

    APP
    Canonical
    2.9 – 2.9.553.6 – 3.6.18
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-5412CRITICAL9.9PL ✓same product

Canonical Juju — nieuprawniony dostęp do poświadczeń chmury przez Controller facade

CVE-2026-4370CRITICAL10.0PL ✓same product

Canonical Juju: brak uwierzytelnienia TLS w klastrze Dqlite umożliwia przejęcie bazy danych

CVE-2017-9232CRITICAL9.8PL ✓same product

Privilege escalation w Juju przez niezabezpieczony UNIX domain socket

CVE-2026-32692HIGH7.6same product

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 thro...

CVE-2026-32693HIGH8.8same product

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correct...