Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ales Stimec

#24688of 55,141
9.9Total CVSS
Vulnerabilities · 1
PT-2026-31912
9.9
2026-04-10
Canonical · Juju · CVE-2026-5412
Name of the Vulnerable Software and Affected Versions Juju versions prior to 2.9.57 and 3.6.21 Description Juju versions prior to 2.9.57 and 3.6.21 contain an authorization issue in the Controller facade. An authenticated user can call the `CloudSpec` API method to extract cloud credentials used for bootstrapping the controller. This allows a low-privileged user to access sensitive credentials. Recommendations Update to Juju version 2.9.57 or later. Update to Juju version 3.6.21 or later.