Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5412

26
FAUCET Score

CVE-2026-5412 is an authorization bypass vulnerability in Juju's Controller facade that affects versions prior to 2.9.57 and 3.6.21. Authenticated users can exploit an insufficiently restricted CloudSpec API method to extract sensitive cloud credentials used during controller bootstrap, compromising the integrity of cloud infrastructure access controls. The vulnerability carries a CVSS score of 9.9 (Critical) with a network attack vector requiring only low-level user privileges. The attack requires no user interaction and impacts confidentiality, integrity, and availability across connected systems. The relatively low EPSS score of 0.00015 suggests minimal exploitation likelihood compared to other disclosed vulnerabilities, though the critical severity rating warrants immediate patching. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has inactive status on security hotlists. However, the straightforward nature of the attack and the critical impact assessment suggest organizations should prioritize upgrading to patched versions 2.9.57 or 3.6.21 to prevent potential credential compromise.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.9.0, < 2.9.57CPE match
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.21CPE match
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
< 2.9.57CPE matchmatch criteria
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
>= 3.6, < 3.6.21CPE matchmatch criteria
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 46th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/juju/jujuFixed in: 0.0.0-20260408003526-d395054dc2c3

Vendor Advisories (1)

goGHSA-w5fq-8965-c969critical

Juju: CloudSpec method leaking cloud credentials

Apr 10, 2026

References

github.com / juju/juju/pull/22205
Issue TrackingPatch
github.com / juju/juju/pull/22206
Issue TrackingPatch
github.com / juju/juju/security/advisories/GHSA-w5fq-8965-c969
ExploitThird Party Advisory