LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-32692

canonical · juju

Published
CVSS7.6
Severityhigh
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Description

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32692

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32692.