logo

Juju’s CVSS 10 Flaw Hands Over Master Cloud Credentials

ID: c008b035-8848-5312-8649-e4cad3e82c7c

STIX ID: report--c008b035-8848-5312-8649-e4cad3e82c7c

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-5412, CVSS 10) in Juju's CloudSpec API lets any authenticated user with basic login permission and knowledge of a controller model UUID retrieve the cloud bootstrap credentials used by the controller. Because bootstrap credentials often grant administrative access to underlying cloud providers (AWS, Azure, GCP), an attacker could bypass Juju and take over cloud infrastructure. Affected releases include Juju 2.9, 3.6 and 4.0.6; administrators are urged to apply patches (2.9.57, 3.6.21) immediately or restrict ingress to controller API port 17070 as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.