logo

CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control

ID: 14e2ad57-b7a9-594c-8d9b-8e4296ce31c2

STIX ID: report--14e2ad57-b7a9-594c-8d9b-8e4296ce31c2

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical authentication flaw (CVE-2026-4370, CVSS 10.0) in Juju's Dqlite cluster allows an attacker with routeability to the controller Dqlite endpoint to join the cluster, read and modify all information, and escalate privileges; official patches are available and administrators are urged to update immediately, with temporary mitigations including restricting access to port 17666, disabling HA, or applying Kubernetes network policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.