CVE-2026-32694 impacts Juju versions 3.0.0 through 3.6.18, where a flaw in secret ownership verification allows a malicious grantee to predict and access past secrets granted by the same owner due to reliance on predictable XIDs. This medium-severity vulnerability (CVSS 6.6) requires a highly privileged attacker and a very specific configuration, including an attacker-controlled application, to achieve high confidentiality, integrity, and availability impact. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.6.19CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.