CVE-2026-32693Disclosure(canonical / juju)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-778CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • juju

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-18); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
juju

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-18: 4Mentions · 2026-03-24: 1Technical Details · 2026-03-18: 3Technical Details · 2026-03-24: 103-1803-24
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-184
Disclosure3General1
2026-03-241
Disclosure1
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32693 - High In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading ... https://www.thehackerwire.com/vulnerability/CVE-2026-32693/ https://t.co/W6MThkUrO2

    Post summary

    The post announces CVE‑2026‑32693, a high‑severity flaw in Juju 3.x that permits unauthorized secret updates and reading, but does not mention a PoC, exploit, or patch.

    0001025
    138 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A high-severity vulnerability (CVE-2026-32693) in `Juju` allows unauthorized access to Kubernetes secrets. Review `Juju` configurations & permissions for `Kubernetes` deployments. #Juju #Kubernetes #infosec https://www.pulsepatch.io/posts/cve-2026-32693-juju-kubernetes-secret-access

    Post summary

    The tweet announces CVE‑2026‑32693 in Juju, noting it permits unauthorized access to Kubernetes secrets and urges reviewing configurations.

    0000071
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32693 In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content,… https://www.cve.org/CVERecord?id=CVE-2026-32693

    Post summary

    The post announces that Juju versions 3.0.0 to 3.6.18 have an authorization flaw in the "secret-set" tool, enabling a grantee to modify secret contents.

    00000115
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32693 Juju Secret-Set Authorization Bypass Vulnerability in Versions 3.0.0-3.6.18 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32693

    Post summary

    A brief mention of CVE-2026-32693 for Juju Secret-Set Authorization Bypass with no additional technical or operational details provided.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32693: HIGH] Weak auth in Juju "secret-set" allows unauthorized updates, impacting secret confidentiality. Exploitation unnoticed due to unexpected behavior logging. Update visible to both parties.#cve,CVE-2026-32693,#cybersecurity https://cvefind.com/CVE-2026-32693

    Post summary

    The entry is a brief disclosure of CVE‑2026‑32693, outlining a weak‑auth flaw in Juju that allows unauthorized secret updates, but it offers no PoC, exploit code, or patch information.

    0000041
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicaljuju---

Explore more