CVE-2026-32693

Source
https://cve.org/CVERecord?id=CVE-2026-32693
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32693.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-32693
Aliases
Downstream
Related
Published
2026-03-18T12:47:02.982Z
Modified
2026-07-15T01:49:21.156982922Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Unauthorized access to Kubernetes secrets in Juju
Details

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32693.json",
    "cwe_ids": [
        "CWE-284",
        "CWE-778",
        "CWE-863"
    ],
    "cna_assigner": "canonical"
}
References

Affected packages

Git / github.com/juju/juju

Affected ranges

Type
GIT
Repo
https://github.com/juju/juju
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.6.19"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32693.json"