VDB

CVE-2026-32693

CVE-2026-32693 PUBLISHED CVSS 8.800000190734863 HIGH

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.

EPSS 0.08% · 24.0th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.08%
24.0th percentile

Affected Products

VendorProductVersions
canonicaljuju3.0.0, 3.0.0
CanonicalJuju3.0.0, 3.0.0
github.comjuju/juju0.0.0-20221021155847-35c560704ee2, *

Timeline

  • Mar 18, 2026 CVE Published
  • Mar 18, 2026 CVE Updated
  • Mar 18, 2026 PoC Published
  • Mar 18, 2026 PoC Published
  • Mar 19, 2026 EPSS Score
  • Mar 19, 2026 PoC Published
  • Mar 20, 2026 EPSS Score
  • Mar 20, 2026 Security Advisory
  • Mar 21, 2026 EPSS Score
  • Mar 22, 2026 EPSS Score
  • Mar 22, 2026 Coalition ESS Score
  • Mar 23, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›