← Back

CVE-2026-32692

nvd nist
Published: Mar 18, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

Affected (1)

Products: Canonical: Juju
1 product
Juju
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.1.6 to 3.6.19

References (1)

Timeline

No history available yet.