
CVE-2026-1237: Ciscoのルータで新たな脆弱性が発表され、CVSS 8.8。影響範囲の広さから、迅速なパッチ適用が求められる。
Post summary
A new vulnerability (CVE-2026-1237) affecting Cisco routers has been disclosed, with a CVSS score of 8.8, and urgent patching is recommended.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE

CVE-2026-1237: Ciscoのルータで新たな脆弱性が発表され、CVSS 8.8。影響範囲の広さから、迅速なパッチ適用が求められる。
Post summary
A new vulnerability (CVE-2026-1237) affecting Cisco routers has been disclosed, with a CVSS score of 8.8, and urgent patching is recommended.

CVE-2026-1237: The Macaroon Mirage: Bypassing Juju's Cross-Model Authorization A logic flaw in Canonical Juju's macaroon validation mechanism allows attackers to bypass cross-model authorization. By presenting a forged macaroon signed with an unknown ... https://cvereports.com/reports/CVE-2026-1237
Post summary
The article discloses a logic flaw in Canonical Juju that permits attackers to forge macaroons and bypass cross‑model authorization, but does not provide a PoC, exploit code, or patch information.

CVE-2026-1237 Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mi… https://www.cve.org/CVERecord?id=CVE-2026-1237
Post summary
The CVE record highlights a cross‑model authorization flaw in Juju that permits malicious database updates when permissions are revoked, but no PoC, exploit, patch, or active exploitation is referenced.