CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control
ID: 14e2ad57-b7a9-594c-8d9b-8e4296ce31c2
STIX ID: report--14e2ad57-b7a9-594c-8d9b-8e4296ce31c2
Feed Name: securityonline.info
Threat Score
A critical authentication flaw (CVE-2026-4370, CVSS 10.0) in Juju's Dqlite cluster allows an attacker with routeability to the controller Dqlite endpoint to join the cluster, read and modify all information, and escalate privileges; official patches are available and administrators are urged to update immediately, with temporary mitigations including restricting access to port 17666, disabling HA, or applying Kubernetes network policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
