Canonical Vulnerabilities and Affected Products
Vulnerabilities associated with Juju.
Products
Clear product- LXD30 vulnerabilities
- apport28 vulnerabilities
- Ubuntu Linux13 vulnerabilities
- Juju12 vulnerabilities
- snapd9 vulnerabilities
- Ubuntu 22.04 LTS8 vulnerabilities
- Ubuntu 24.04 LTS8 vulnerabilities
- Ubuntu 20.04 LTS7 vulnerabilities
- Ubuntu 26.04 LTS7 vulnerabilities
- Ubuntu 16.04 LTS6 vulnerabilities
- Ubuntu 18.04 LTS6 vulnerabilities
- ubuntu_linux6 vulnerabilities
- Multipass5 vulnerabilities
- Python-apt4 vulnerabilities
- aptdaemon3 vulnerabilities
- cloud-init3 vulnerabilities
- pulseaudio3 vulnerabilities
- Ubuntu3 vulnerabilities
- ubuntu-pro-client (ubuntu-advantage-tools)3 vulnerabilities
- authd2 vulnerabilities
- Subiquity2 vulnerabilities
- ubantu_kernel2 vulnerabilities
- Ubuntu 14.04 LTS2 vulnerabilities
- Ubuntu Kernel2 vulnerabilities
- unity-firefox-extension2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-5412CRITICAL | Juju CloudSpec API could leak senstive informationIn Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21. CWE-285Apr 10, 2026 | CVSS9.9v3.1 | EPSS0.445% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-5774MEDIUM | Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token MapImproper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token. CWE-362Apr 10, 2026 | CVSS6.1v4.0 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4370CRITICAL | Improper TLS Client/Server authentication and certificate verification on Database ClusterA vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once join… | CVSS10.0v3.1 | EPSS0.381% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32694MEDIUM | Insecure Direct Object Reference attack via predictable secret ID in JujuIn Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which can request secrets to predict past secrets granted by the same secret owner to different grantees, allowing them to use the resources granted by those past secrets. Successful exploitation relies on a very specific configuration, specific data semantic, and the… | CVSS6.6v3.1 | EPSS0.269% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32693HIGH | Unauthorized access to Kubernetes secrets in JujuIn Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee. | CVSS8.8v3.1 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32692HIGH | Unauthorized update of out-of-scope Vault secretsAn authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end. CWE-285Mar 18, 2026 | CVSS7.6v3.1 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32691MEDIUM | Timing ownership claim attack on new external back-end secretsA race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision. CWE-708Mar 18, 2026 | CVSS5.3v3.1 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Juju has broken CMR authorizationVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing. | CVSS2.1v4.0 | EPSS0.133% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-0928HIGH | Arbitrary executable upload via authenticated endpointIn Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution. | CVSS8.8v3.1 | EPSS0.583% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53513HIGH | Zip slip vulnerability in JujuThe /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm. | CVSS8.8v3.1 | EPSS0.662% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53512MEDIUM | Sensitive log retrieval in JujuThe /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information. | CVSS6.5v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6984HIGH | An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm. CWE-209Jul 29, 2024 | CVSS8.8v3.1 | EPSS0.379% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |