CVE-2026-1237Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347CWE-672

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-06-13: 1Patch / Workaround · 2026-06-13: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-06-13: 101-2801-2906-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • takenaka hiroya@Joe_Biden_ja
    Disclosure

    CVE-2026-1237: Ciscoのルータで新たな脆弱性が発表され、CVSS 8.8。影響範囲の広さから、迅速なパッチ適用が求められる。

    Post summary

    A new vulnerability (CVE-2026-1237) affecting Cisco routers has been disclosed, with a CVSS score of 8.8, and urgent patching is recommended.

    0000089
    564 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-1237: The Macaroon Mirage: Bypassing Juju's Cross-Model Authorization A logic flaw in Canonical Juju's macaroon validation mechanism allows attackers to bypass cross-model authorization. By presenting a forged macaroon signed with an unknown ... https://cvereports.com/reports/CVE-2026-1237

    Post summary

    The article discloses a logic flaw in Canonical Juju that permits attackers to forge macaroons and bypass cross‑model authorization, but does not provide a PoC, exploit code, or patch information.

    0000064
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1237 Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mi… https://www.cve.org/CVERecord?id=CVE-2026-1237

    Post summary

    The CVE record highlights a cross‑model authorization flaw in Juju that permits malicious database updates when permissions are revoked, but no PoC, exploit, patch, or active exploitation is referenced.

    00000171
    56.5K followersView on X

Explore more