PT-2026-30120 · Canonical · Juju

CVE-2025-68152

·

Published

2026-04-03

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Juju versions 2.9 through 2.9.55 and 3.6 through 3.6.18
Description A compromised workload machine under a Juju controller could potentially read any log file for any entity in any model at any level. This affects the application orchestration engine Juju.
Recommendations Update to Juju version 2.9.56 or later. Update to Juju version 3.6.19 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68152
GHSA-J6F6-JP3P-53MW
GO-2026-5451
OPENSUSE-SU-2026:21483-1

Affected Products

Juju