Juju’s CVSS 10 Flaw Hands Over Master Cloud Credentials
ID: c008b035-8848-5312-8649-e4cad3e82c7c
STIX ID: report--c008b035-8848-5312-8649-e4cad3e82c7c
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-5412, CVSS 10) in Juju's CloudSpec API lets any authenticated user with basic login permission and knowledge of a controller model UUID retrieve the cloud bootstrap credentials used by the controller. Because bootstrap credentials often grant administrative access to underlying cloud providers (AWS, Azure, GCP), an attacker could bypass Juju and take over cloud infrastructure. Affected releases include Juju 2.9, 3.6 and 4.0.6; administrators are urged to apply patches (2.9.57, 3.6.21) immediately or restrict ingress to controller API port 17070 as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
