CVE-2026-5774
EUVD-2026-2136610.04.2026, 13:16
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| canonical | juju | 𝑥 < 2.9.57 |
| canonical | juju | 3.0 ≤ 𝑥 < 3.6.21 |
| canonical | juju | 4.0 ≤ 𝑥 < 4.0.6 |
𝑥
= Vulnerable software versions