OVERVIEW CVE-2026-5774 is an improper synchronization vulnerability affecting the userTokens map in the API server of Canonical Juju versions 4.0.5, 3.6.20, and 2.9.56. An authenticated user can exploit this flaw to either deny service to the server or reuse single-use discharge tokens, potentially gaining unauthorized access. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.4 (MEDIUM) with a network-based attack vector requiring low privileges and high attack complexity. The impact is significant, with potential consequences including service disruption (high availability impact), information disclosure (low confidentiality impact), and token manipulation (low integrity impact). The FAUCET Risk Score of 44.0 out of 100 indicates moderate risk. EXPLOITATION STATUS There is no current evidence of active exploitation. The CVE is not listed on the Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00011 suggests negligible probability of exploitation in the wild relative to other CVEs. The vulnerability remains inactive on threat tracking lists, indicating limited community attention and no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.9.57CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.6.21CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.6CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
< 2.9.57CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
>= 3.0, < 3.6.21CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.