CVE-2026-5412 is an authorization bypass vulnerability in Juju's Controller facade that affects versions prior to 2.9.57 and 3.6.21. Authenticated users can exploit an insufficiently restricted CloudSpec API method to extract sensitive cloud credentials used during controller bootstrap, compromising the integrity of cloud infrastructure access controls. The vulnerability carries a CVSS score of 9.9 (Critical) with a network attack vector requiring only low-level user privileges. The attack requires no user interaction and impacts confidentiality, integrity, and availability across connected systems. The relatively low EPSS score of 0.00015 suggests minimal exploitation likelihood compared to other disclosed vulnerabilities, though the critical severity rating warrants immediate patching. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has inactive status on security hotlists. However, the straightforward nature of the attack and the critical impact assessment suggest organizations should prioritize upgrading to patched versions 2.9.57 or 3.6.21 to prevent potential credential compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.9.0, < 2.9.57CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.6.21CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
< 2.9.57CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 3.6, < 3.6.21CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.