Authorization Bypass Vulnerability in Juju Vault Secrets Implementation
CVE-2026-32692
7.6HIGH
What is CVE-2026-32692?
An authorization bypass vulnerability exists in the Vault secrets back-end of Juju from version 3.1.6 to 3.6.18. This flaw allows an authenticated unit agent to execute unauthorized updates to secret revisions, potentially enabling an attacker with adequate information to corrupt any existing secret revision associated with that Vault secret back-end. It poses a risk to the integrity of sensitive data managed within Juju's secrets framework.
Affected Version(s)
Juju Linux 3.1.6 < 3.6.19
