๐Ÿ” CVE Alert

CVE-2026-32691

MEDIUM 5.3

Timing ownership claim attack on new external back-end secrets

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

CWE CWE-708
Vendor canonical
Product juju
Ecosystems
Industries
Technology
Published Mar 18, 2026
Last Updated Mar 18, 2026
Stay Ahead of the Next One

Get instant alerts for canonical juju

Be the first to know when new medium vulnerabilities affecting canonical juju are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Canonical / Juju
3.0.0 < 3.6.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/juju/juju/security/advisories/GHSA-gfgr-6hrj-85ww

Credits

Harry Pidcock