CVE-2026-5774
EUVD-2026-2136610.04.2026, 13:16
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canonical | juju | 2.0.0 ≤ 𝑥 < 2.9.57 | CNA |
| canonical | juju | 3.0.0 ≤ 𝑥 < 3.6.21 | CNA |
| canonical | juju | 4.0.0 ≤ 𝑥 < 4.0.6 | CNA |