


Perceptive Security
SOC/SIEM Consultancy

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to p…
Published:
17 maart 2026 om 23:00:00
Alert date:
18 maart 2026 om 15:08:05
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
An authorization bypass vulnerability affects Juju versions 3.1.6 through 3.6.18 in the Vault secrets back-end implementation. The vulnerability allows authenticated unit agents to perform unauthorized updates to secret revisions. Attackers with sufficient information can poison existing secret revisions within the Vault secret back-end scope. This represents a significant security risk for organizations using affected Juju versions with Vault integration. The vulnerability impacts secret management functionality and could lead to compromise of sensitive data.
Technical details
Mitigation steps:
Affected products:
Juju
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32692
https://github.com/juju/juju/security/advisories/GHSA-89x7-5m5m-mcmm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
