Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee. | |
| Title | Unauthorized access to Kubernetes secrets in Juju | |
| Weaknesses | CWE-284 CWE-778 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-03-18T13:19:58.719Z
Reserved: 2026-03-13T12:53:34.544Z
Link: CVE-2026-32693
Updated: 2026-03-18T13:18:07.248Z
Status : Received
Published: 2026-03-18T13:16:18.860
Modified: 2026-03-18T13:16:18.860
Link: CVE-2026-32693
No data.
OpenCVE Enrichment
No data.