CVE-2026-5412Disclosure(canonical / juju)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch canonical juju systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • juju

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 12 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 5 mentions (2026-04-10); latest day: 4
  • 15 total mentions across 7 days

Affected systems

Vendors
Products
juju

Deep dive

Activity timeline15 mentions / 7d
01345Mentions · 2026-04-10: 5Mentions · 2026-04-11: 2Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-18: 1Mentions · 2026-04-28: 1Mentions · 2026-05-14: 4PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-10: 4Technical Details · 2026-04-11: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-14: 304-1004-1104-1204-1404-1804-2805-14
Signal classification3 categories
Disclosure
1066.7%
General
320.0%
Patch
213.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-105
Disclosure4Patch1
2026-04-112
Disclosure1General1
2026-04-121
Disclosure1
2026-04-141
Disclosure1
2026-04-181
Patch1
2026-04-281
Disclosure1
2026-05-144
Disclosure2General2
Full discourse15 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Juju's critical CVSS 10 flaw (CVE-2026-5412) allows low-level users to steal master cloud credentials. Secure your AWS/Azure/GCP environments—upgrade now! #Juju #CloudSecurity #InfoSec #CyberSecurity #PatchNow #CVSS10 #Vulnerability https://securityonline.info/juju-cvss-10-vulnerability-cloud-credential-exfiltration-cve-2026-5412/ https://t.co/sVLX7HkH9y

    Post summary

    A CVSS 10 flaw (CVE‑2026‑5412) in Juju lets low‑privilege users exfiltrate master cloud credentials; the post urges users to upgrade AWS/Azure/GCP environments to mitigate the risk.

    03062478
    12.3K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE‑2026‑5412 – Juju authorization bypass (Critical) 🔐: In Juju prior to 2.9.57 and 3.6.21, an authorization issue in the Controller facade allows unauthenticated attackers to perform privileged operations on the model, enabling remote take‑over of the Juju environment. CVSS 9.9, patched in 2026‑04‑10. https://cvefind.com/CVE-2026-5412 #CVE20265412 #Juju#AuthBypass #RCE #AppSec #ThreatIntel

    Post summary

    The post announces CVE‑2026‑5412 as a critical Juju authorization bypass, provides technical details and CVSS score, and notes the patch release date.

    21070158
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-5412 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry merely lists the CVE identifier, its CVSS score, severity, and advisory status, with no additional information on exploitation, mitigation, or proof of concept.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-5412 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade.

    Post summary

    A critical advisory for CVE-2026-5412 highlights an authorization flaw in Juju with a high CVSS score, but no PoC, exploit, or patch details are provided.

    1000026
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-5412 (CVSS 9.9) — canonical juju. CVE: CVE-2026-5412 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post is a brief vulnerability advisory announcing CVE‑2026‑5412 with a critical severity score and detailed CVSS metrics, but it provides no exploit, PoC, or mitigation information.

    1000028
    210 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40175 | CVSS 10.0 🔴 CVE-2026-4149 | CVSS 10.0 🔴 CVE-2026-5412 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet simply lists three newly disclosed high‑severity CVEs with their CVSS scores, without providing PoC, exploit code, patches, or active exploitation evidence.

    00001422
    5.6K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-5412-canonical-juju #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet simply links to a research page about CVE‑2026‑5412 without providing any additional details or actionable information.

    0000019
    210 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-5412: CVE-2026-5412: Broken Access Control in Juju API Leads to Cloud Credential Leak CVE-2026-5412 is a critical improper authorization vulnerability within the Canonical Juju API server. Low-privileged authenticated users can bypass authori... https://cvereports.com/reports/CVE-2026-5412

    Post summary

    The text announces a critical broken access control flaw in Canonical Juju’s API that allows low‑privileged authenticated users to leak cloud credentials, but offers no PoC, exploit, or mitigation.

    0000044
    36 followersView on X
  • Virus Myths!@virusmyths
    Patch

    juju 정보 유출(CVE-2026-5412) 취약점 패치 설치 권고 (출처 : Virus My.. | 블로그) https://m.blog.naver.com/nologout/224253595734

    Post summary

    A blog post reports the CVE‑2026‑5412 information‑leak vulnerability in Juju and advises readers to install the available patch.

    0000030
    21 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5412 📊 Severity: 9.9 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5412 #CVE-2026-5412 #CVE #Critical #CyberSecurity #InfoSec https://t.co/ZZJOfTTfuu

    Post summary

    The tweet announces the new CVE-2026-5412 with a critical severity rating, but provides no technical details, exploit availability, patch information, or evidence of active exploitation.

    0000040
    125 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical vulnerability (CVE-2026-5412) in `Juju`'s CloudSpec method can leak cloud credentials, risking unauthorized access to infrastructure. Review `Juju` configurations and monitor for patches. #CloudSecurity #Juju #CVE https://www.pulsepatch.io/posts/cve-2026-5412-juju-cloudspec-credential-leak

    Post summary

    The tweet announces a critical CVE that could leak cloud credentials and urges users to review configurations and await patches.

    00000110
    11 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5412: CRITICAL] Critical cyber security flaw in older Juju versions could lead to unauthorized access of cloud credentials. Update to versions 2.9.57 or 3.6.21 to mitigate this vulnerability.#cve,CVE-2026-5412,#cybersecurity https://cvefind.com/CVE-2026-5412

    Post summary

    CVE-2026-5412 poses a critical flaw in older Juju versions, compromising cloud credentials; upgrading to 2.9.57 or 3.6.21 resolves the issue.

    0000067
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5412 In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract … https://www.cve.org/CVERecord?id=CVE-2026-5412 ----- Traducción: CVE-2026-5412 En … http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑5412 as an authorization flaw in Juju’s Controller facade that lets authenticated users extract data via the CloudSpec API, with no PoC, exploit code, or patch information included.

    0000036
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5412 In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract … https://www.cve.org/CVERecord?id=CVE-2026-5412

    Post summary

    The text provides initial technical details about CVE-2026-5412, describing an authorization flaw in Juju's Controller facade, but contains no exploits, patches, or evidence of active exploitation.

    00000338
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5412: Juju CloudSpec API could leak sen... CloudSpec API hands out bootstrap credentials to any authenticated user - trivial privilege escalation in multi-tenant J... https://zerodaysignal.com/vulnerability/CVE-2026-5412 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑5412, noting that the Juju CloudSpec API improperly exposes bootstrap credentials to any authenticated user, allowing trivial privilege escalation in multi‑tenant setups.

    0000071
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicaljuju---

Explore more