CVE-2026-5774
Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
| CWE | CWE-362 |
| Vendor | canonical |
| Product | juju |
| Ecosystems | |
| Industries | Technology |
| Published | Apr 10, 2026 |
| Last Updated | Apr 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for canonical juju
Be the first to know when new unknown vulnerabilities affecting canonical juju are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Canonical / Juju
2.0.0 < 2.9.57 3.0.0 < 3.6.21 4.0.0 < 4.0.6