CVE-2026-4370Disclosure(canonical / juju)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch canonical juju systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • juju

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-04-01); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
juju

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-04-01: 4Mentions · 2026-04-02: 2Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-15: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-01: 4Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 2Technical Details · 2026-04-05: 1Technical Details · 2026-04-15: 104-0104-0204-0304-0404-0504-15
Signal classification3 categories
Disclosure
654.5%
Patch
436.4%
General
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-014
Disclosure3Patch1
2026-04-022
General1Patch1
2026-04-032
Disclosure1Patch1
2026-04-041
Disclosure1
2026-04-051
Disclosure1
2026-04-151
Patch1
Full discourse11 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚨 CVE-2026-4370 — CVSS 10.0 Canonical Juju Dqlite Auth Bypass An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can join the database cluster. No credentials needed. Affects Juju 3.2.0-3.6.19 & 4.0.0-4.0.4 ✅ Patch: 3.6.20 / 4.0.5 CWE-295: Improper TLS certificate validation Source: http://nvd.nist.gov/vuln/detail/CVE-2026-4370 #CVE #Juju #Canonical #Kubernetes #InfoSec #CyberSecurity

    Post summary

    A critical Juju Dqlite authentication bypass (CVE-2026-4370) has been disclosed with a CVSS of 10.0, affecting specified Juju versions; patches 3.6.20/4.0.5 are available to mitigate the issue.

    1003066
    1.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Juju hits a perfect 10.0 CVSS score (CVE-2026-4370). A TLS flaw on port 17666 lets attackers hijack clusters. Update to 3.6.20 or 4.0.5 now! #Juju #CVE20264370 #CloudSecurity #CyberSecurity #Kubernetes #Infosec #Canonical #PatchAlert https://securityonline.info/juju-critical-vulnerability-cvss-10-cve-2026-4370/ https://t.co/4rsDxDoDQd

    Post summary

    The tweet announces the CVE-2026-4370 TLS flaw with a 10.0 CVSS score and urges users to apply the 3.6.20 or 4.0.5 patch to mitigate the risk.

    00022360
    12.3K followersView on X
  • maruomosquit@maru1151157
    Patch

    🚨 CVE-2026-4370 (CVSS: 10.0) Juju 3.2.0~3.6.19、4.0~4.0.4でDqliteクラスターのTLS認証不備により、未認証アタッカーがデータベースに接続可能。対策: 対応バージョンにアップグレード。 https://maruomosquit.com/vulnerability/CVE-2026-4370/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-4370 is a critical TLS authentication flaw in Juju that enables unauthenticated attackers to connect to the dqlite database, and users are advised to upgrade to patched versions.

    0000034
    1.4K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control https://securityonline.info/juju-critical-vulnerability-cvss-10-cve-2026-4370/

    Post summary

    The post announces CVE-2026-4370 with a CVSS 10 score but lacks technical specifics, PoC, or mitigation guidance.

    0000053
    234 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Critical vulnerability (CVE-2026-4370) in `Juju` database cluster TLS authentication could lead to data compromise. Review TLS configurations and network access for database connections. #Juju #infosec #cybersecurity https://www.pulsepatch.io/posts/cve-2026-4370-juju-improper-tls-authentication

    Post summary

    A new critical CVE (CVE‑2026‑4370) affecting Juju’s TLS authentication has been disclosed, highlighting the need to review TLS configurations; no evidence of exploitation or patch availability is mentioned.

    0000069
    10 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34570 | CVSS 10.0 🔴 CVE-2026-4370 | CVSS 10.0 🔴 CVE-2026-34569 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three CVE identifiers with high CVSS scores and a link to a vulnerabilities page, but offers no details on exploits, PoCs, patches, or active exploitation.

    0000025
    5.6K followersView on X
  • CosmicBytez@CosmicBytez
    Patch

    Security Advisory: Juju Dqlite Cluster TLS Auth Bypass — Unauthenticated Database Access (CVE-2026-4370) https://labs.cosmicbytez.ca/security/cve-2026-4370 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces a TLS authentication bypass in Juju Dqlite Cluster (CVE‑2026‑4370) that enables unauthenticated database access, highlighting that a vendor patch exists but offers no PoC or exploitation details.

    0000034
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4370 A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform pro… https://www.cve.org/CVERecord?id=CVE-2026-4370

    Post summary

    The post announces CVE‑2026‑4370, detailing that Juju versions 3.2.0‑3.6.19 and 4.0‑4.0.4 are affected by a database cluster issue, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000068
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4370: CRITICAL] Critical vulnerability in Juju versions 3.2.0 to 3.6.19 and 4.0 to 4.0.4 exposes databases to unauthorized access. Ensure proper TLS client and server authentication.#cve,CVE-2026-4370,#cybersecurity https://cvefind.com/CVE-2026-4370

    Post summary

    A critical Juju vulnerability allows unauthorized database access, and admins are advised to enforce proper TLS client and server authentication to mitigate the risk.

    0000046
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4370 - Critical A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and s... https://www.thehackerwire.com/vulnerability/CVE-2026-4370/ https://t.co/mCydqKPKJm

    Post summary

    CVE-2026-4370 is a newly disclosed critical vulnerability affecting Juju versions 3.2.0‑3.6.19 and 4.0‑4.0.4, where the internal Dqlite database cluster fails to properly authenticate TLS clients.

    0000036
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4370: Improper TLS Client/Server authen... Network-reachable Dqlite cluster with zero auth checks = instant database takeover for any script kiddie who can reach p... https://zerodaysignal.com/vulnerability/CVE-2026-4370 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-4370 as a critical authentication flaw in Dqlite clusters that allows immediate database takeover, but no exploit code or active exploitation evidence is provided.

    0000076
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicaljuju---

Explore more