216.73.217.22

CVE-2026-32693

· Published 18/03/2026 13:16 · Modified 19/03/2026 15:17

Labels: CVE-2026-32693 2026-03-18CVE-2026-32693CWE-284[email protected]

Essential information

Published
18/03/2026 13:16
Modified
19/03/2026 15:17
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
canonical / juju cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*

References