CVE-2026-32693
8.8Canonical · Juju
A flaw in Juju versions 3.0.0 through 3.6.18 allows authenticated grantees to improperly modify or access secrets due to incorrect authorization checks in the secret-set tool.
Executive summary
A high severity authorization vulnerability in Canonical Juju allows authenticated users to gain unauthorized access to or modify system secrets.
Vulnerability
The vulnerability involves incorrect authorization in the secret-set tool, which permits an authenticated grantee to update secret content beyond their intended permissions. This flaw allows unauthorized reading or modification of secrets, even when error logs indicate a failed operation.
Business impact
The ability for unauthorized users to access or manipulate secrets poses a significant risk to the integrity and confidentiality of the entire managed environment. Because Juju manages secrets for distributed applications, this compromise could lead to lateral movement, credential theft, or the disruption of critical services. With a CVSS score of 8.8, this vulnerability is categorized as high severity and requires immediate attention to prevent unauthorized data exposure.
Remediation
Immediate Action: Upgrade Canonical Juju to version 3.6.19 or the latest available release containing the fix provided by the vendor.
Proactive Monitoring: Review Juju access logs for unusual activity involving the secret-set tool or unexpected modifications to secret values by non-owner accounts.
Compensating Controls: Implement strict identity and access management policies to limit the number of users with grantee access to sensitive secrets until the patch is applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for full secret compromise, organizations should prioritize upgrading their Juju installations immediately. Ensure all administrative teams are aware of the flaw and verify that secret access permissions are audited following the update to confirm no unauthorized changes occurred during the vulnerable period.
More Canonical CVEs
Sources
Originally found and disclosed by Dima Tisnek, per the CVE Program record.