Authorization Issue in Juju Controller Facade Exposes Cloud Credentials
CVE-2026-5412
9.9CRITICAL
What is CVE-2026-5412?
An authorization vulnerability in Juju's Controller facade allows authenticated users to exploit the CloudSpec API method, leading to the unauthorized retrieval of cloud credentials. This issue grants low-privileged users access to sensitive information essential for bootstrapping the controller. To mitigate this risk, users are advised to update to Juju versions 2.9.57 or 3.6.21, where this vulnerability has been effectively resolved.
Affected Version(s)
Juju Linux 2.9.0 < 2.9.57
Juju Linux 3.6.0 < 3.6.21
