CVE-2026-32693 identifies an authorization bypass vulnerability in the "secret-set" tool within Canonical Juju versions 3.0.0 through 3.6.18. This flaw permits a grantee with low privileges to update secret content, potentially enabling unauthorized reading or modification of other secrets, even if an error is logged during the attempt. With a CVSS score of 8.8 HIGH (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), it poses a significant risk to confidentiality, integrity, and availability over the network with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or notable community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.6.19CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.