PT-2026-26056 · Canonical · Juju
Harry Pidcock
·
Publicado
2026-03-18
·
Atualizado
2026-03-27
·
CVE-2026-32692
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Juju versions 3.1.6 through 3.6.18
Description
An authorization bypass exists in the Vault secrets back-end implementation. An authenticated unit agent can perform unauthorized updates to secret revisions. An attacker, with sufficient information, can potentially compromise existing secret revisions within the scope of the affected Vault secret back-end.
Recommendations
Update Juju to version 3.6.19 or later.
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Juju