VDB
CVE-2026-32693
CVE-2026-32693
PUBLISHED
CVSS 8.800000190734863 HIGH
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.
EPSS 0.08% · 24.0th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.08%
24.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| canonical | juju | 3.0.0, 3.0.0 |
| Canonical | Juju | 3.0.0, 3.0.0 |
| github.com | juju/juju | 0.0.0-20221021155847-35c560704ee2, * |
Exploit Intelligence
- CIRCL seen: CVE-2026-32693 (circl-sighting)
- CIRCL seen: CVE-2026-32693 (circl-sighting)
- CIRCL seen: CVE-2026-32693 (circl-sighting)
- https://github.com/juju/juju/security/advisories/GHSA-439w-v2p7-pggc (nist-nvd)
Timeline
- Mar 18, 2026 CVE Published
- Mar 18, 2026 CVE Updated
- Mar 18, 2026 PoC Published
- Mar 18, 2026 PoC Published
- Mar 19, 2026 EPSS Score
- Mar 19, 2026 PoC Published
- Mar 20, 2026 EPSS Score
- Mar 20, 2026 Security Advisory
- Mar 21, 2026 EPSS Score
- Mar 22, 2026 EPSS Score
- Mar 22, 2026 Coalition ESS Score
- Mar 23, 2026 EPSS Score