CVE-2026-32691
EUVD-2026-1281518.03.2026, 13:16
A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canonical | juju | 3.0.0 ≤ 𝑥 < 3.6.19 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration