Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/juju/juju
  4. ›
  5. CVE-2026-32692

CVE-2026-32692: Juju has unauthorized update of out-of-scope Vault secrets

March 19, 2026

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

References

  • github.com/advisories/GHSA-89x7-5m5m-mcmm
  • github.com/juju/juju
  • github.com/juju/juju/commit/d06919eb03ec68156818bcc304b5fe1c39a8f9e9
  • github.com/juju/juju/security/advisories/GHSA-89x7-5m5m-mcmm
  • nvd.nist.gov/vuln/detail/CVE-2026-32692

Code Behaviors & Features

Detect and mitigate CVE-2026-32692 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.0-20230919230135-f6a66aa91eec before 0.0.0-20260319091847-d06919eb03ec

Fixed versions

  • 0.0.0-20260319091847-d06919eb03ec

Solution

Upgrade to version 0.0.0-20260319091847-d06919eb03ec or above.

Impact 7.6 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-285: Improper Authorization

Source file

go/github.com/juju/juju/CVE-2026-32692.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:20:20 +0000.