Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5774

24
FAUCET Score

OVERVIEW CVE-2026-5774 is an improper synchronization vulnerability affecting the userTokens map in the API server of Canonical Juju versions 4.0.5, 3.6.20, and 2.9.56. An authenticated user can exploit this flaw to either deny service to the server or reuse single-use discharge tokens, potentially gaining unauthorized access. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.4 (MEDIUM) with a network-based attack vector requiring low privileges and high attack complexity. The impact is significant, with potential consequences including service disruption (high availability impact), information disclosure (low confidentiality impact), and token manipulation (low integrity impact). The FAUCET Risk Score of 44.0 out of 100 indicates moderate risk. EXPLOITATION STATUS There is no current evidence of active exploitation. The CVE is not listed on the Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00011 suggests negligible probability of exploitation in the wild relative to other CVEs. The vulnerability remains inactive on threat tracking lists, indicating limited community attention and no publicly available exploit code at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.9.57CPE match
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.6.21CPE match
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.0.6CPE match
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
< 2.9.57CPE matchmatch criteria
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*
>= 3.0, < 3.6.21CPE matchmatch criteria
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.0MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 15th percentile among its peer group of 1,428 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/juju/jujuFixed in: 0.0.0-20260408003526-d395054dc2c3

Vendor Advisories (1)

goGHSA-7m55-2hr4-pw78medium

Juju: In-Memory Token Store for Discharge Tokens Lacks Concurrency Safety and Persistence

Apr 10, 2026

References

github.com / juju/juju/pull/22205
Issue Tracking
github.com / juju/juju/pull/22206
Issue Tracking
github.com / juju/juju/security/advisories/GHSA-7m55-2hr4-pw78
ExploitThird Party Advisory