HIGH🇵🇱 Wersja polska

CVE-2026-32692

CVSS 7.6v3.1pub. 2026-03-18upd. 2026-03-19

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
  • Canonical Juju

    APP
    Canonical
    3.1.6 – 3.6.19 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-5412CRITICAL9.9PL ✓same product

Canonical Juju — nieuprawniony dostęp do poświadczeń chmury przez Controller facade

CVE-2026-4370CRITICAL10.0PL ✓same product

Canonical Juju: brak uwierzytelnienia TLS w klastrze Dqlite umożliwia przejęcie bazy danych

CVE-2017-9232CRITICAL9.8PL ✓same product

Privilege escalation w Juju przez niezabezpieczony UNIX domain socket

CVE-2025-68153HIGH7.1same product

Juju is an open source application orchestration engine that enables any application operation on any infrastr...

CVE-2026-32693HIGH8.8same product

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correct...