Authorization Issue in Juju Controller Facade Exposes Cloud Credentials
CVE-2026-5412

9.9CRITICAL

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-5412?

An authorization vulnerability in Juju's Controller facade allows authenticated users to exploit the CloudSpec API method, leading to the unauthorized retrieval of cloud credentials. This issue grants low-privileged users access to sensitive information essential for bootstrapping the controller. To mitigate this risk, users are advised to update to Juju versions 2.9.57 or 3.6.21, where this vulnerability has been effectively resolved.

Affected Version(s)

Juju Linux 2.9.0 < 2.9.57

Juju Linux 3.6.0 < 3.6.21

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ales Stimec
.