CVE-2026-5774Disclosure(canonical / juju)

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • juju

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
juju

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-28: 104-1004-1104-1204-28
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure1General1
2026-04-111
General1
2026-04-121
Disclosure1
2026-04-281
Disclosure1
Full discourse5 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-5774: CVE-2026-5774: Race Condition and Denial of Service in Canonical Juju API Server Canonical Juju is affected by a medium-severity race condition vulnerability (CWE-362) within its API server. The vulnerability allows an authenticated att... https://cvereports.com/reports/CVE-2026-5774

    Post summary

    A medium‑severity race condition (CWE‑362) CVE‑2026‑5774 affecting Canonical Juju’s API server has been disclosed, though no PoC, exploit code, active exploitation, patch, or debunking claim is mentioned.

    0000028
    36 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5774 📊 Severity: 6.0 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5774 #CVE-2026-5774 #CVE #Medium #CyberSecurity #InfoSec https://t.co/IWMDUrA99A

    Post summary

    The tweet announces a new CVE (CVE‑2026‑5774) with a medium severity score of 6.0 affecting unspecified products, linking only to the NVD entry.

    0000036
    125 followersView on X
  • DailyCVE@dailycve
    General

    🟠 Juju API Server, Race Condition, #CVE-2026-5774 (Moderate) https://dailycve.com/juju-api-server-race-condition-cve-2026-5774-moderate/

    Post summary

    The tweet merely notes a moderate race condition vulnerability (CVE-2026-5774) affecting Juju’s API Server, without providing any PoC, exploit, fix, or evidence of active exploitation.

    0000047
    181 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5774 Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial … https://www.cve.org/CVERecord?id=CVE-2026-5774 ----- Traducción: CVE-2026-5774 Sin… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-5774, describing an improper synchronization issue in Canonical Juju that could lead to a denial‑of‑service when accessed by an authenticated user, without any indication of exploitation or mitigation.

    0000035
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5774 Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial … https://www.cve.org/CVERecord?id=CVE-2026-5774

    Post summary

    The post references CVE-2026-5774, describing an improper synchronization issue that could lead to denial of service for authenticated users, but provides no additional context such as PoC, exploit code, or patches.

    00000277
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcanonicaljuju---

Explore more