CVE-2026-32691 identifies a race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18. This flaw allows an authenticated unit agent to claim ownership of a newly initialized secret, enabling them to read its confidential content. Rated as Medium severity (CVSS 5.3), the vulnerability has a network attack vector and requires low privileges, but its exploitation complexity is high due to the timing-sensitive race condition. Currently, there is no indication of active exploitation, public exploit code availability, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.6.19CPE match | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Juju affected by timing ownership claim attack on new external back-end secrets
Mar 19, 2026Juju affected by timing ownership claim attack on new external back-end secrets
Mar 19, 2026Juju affected by timing ownership claim attack on new external back-end secrets
Mar 19, 2026