← Back

CVE-2026-5412

nvd nist
Published: Apr 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

Affected (2)

Products: Canonical: Juju
1 product
Juju
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Before 2.9.57
From 3.6 to 3.6.21

References (3)

Source: security@ubuntu.com
Issue TrackingPatch
Source: security@ubuntu.com
Issue TrackingPatch
Source: security@ubuntu.com
ExploitThird Party Advisory

Timeline

No history available yet.