Juju
Vendor:
First CVE: May 28, 2017 · Active for 9 years
19
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Juju over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2017
9 years ago
Most Recent CVE
Apr 10, 2026
109 days ago
CVE Severity & Scoring
Juju19 CVEs
63%
21%
11%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (15.8%)
Network15 (78.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low15 (78.9%)
High4 (21.1%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low13 (68.4%)
High3 (15.8%)
None3 (15.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9232CRITICAL Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the sys | May 28, 2017 | 9.8 | 76 | NO | YES |
CVE-2026-4370CRITICAL A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS clie | Apr 1, 2026 | 10.0 | 35 | NO | NO |
CVE-2026-32693HIGH In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead | Mar 18, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-5412MEDIUM In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud cr | Apr 10, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-5774MEDIUM Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service o | Apr 10, 2026 | 6.4 | 24 | NO | NO |
CVE-2025-68153MEDIUM Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From ve | Apr 3, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-32694MEDIUM In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret t | Mar 18, 2026 | 6.6 | 23 | NO | NO |
CVE-2025-0928HIGH In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verif | Jul 8, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-7558HIGH JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespa | Oct 2, 2024 | 8.0 | 23 | NO | NO |
CVE-2026-32692MEDIUM An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized | Mar 18, 2026 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.3% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Juju
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.2 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.1.1 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.1.0 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.0.3 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.0.2 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.0.1 | 1 | 9.8 | 48.5% | 0 | 1 |
| 2.0.0 | 1 | 9.8 | 48.5% | 0 | 1 |