An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical juju |
|
| Vendors & Products |
Canonical
Canonical juju |
Wed, 18 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end. | |
| Title | Unauthorized update of out-of-scope Vault secrets | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published: 2026-03-18T12:35:29.274Z
Updated: 2026-03-18T13:42:54.697Z
Reserved: 2026-03-13T12:53:34.544Z
Link: CVE-2026-32692
Updated: 2026-03-18T13:42:50.071Z
Status : Analyzed
Published: 2026-03-18T13:16:18.710
Modified: 2026-03-19T15:23:26.870
Link: CVE-2026-32692
No data.