Vulnerability Description
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Juju | < 2.9.57 |
Related Weaknesses (CWE)
References
- https://github.com/juju/juju/pull/22205Issue TrackingPatch
- https://github.com/juju/juju/pull/22206Issue TrackingPatch
- https://github.com/juju/juju/security/advisories/GHSA-w5fq-8965-c969ExploitThird Party Advisory
FAQ
What is CVE-2026-5412?
CVE-2026-5412 is a vulnerability with a CVSS score of 9.9 (CRITICAL). In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bo...
How severe is CVE-2026-5412?
CVE-2026-5412 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-5412?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Juju.