Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/juju/juju
  4. ›
  5. CVE-2026-32694

CVE-2026-32694: Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju Secrets

March 19, 2026 (updated April 17, 2026)

Predictable secret ID and lack of secret origin API enable confused deputy attacks on Juju workloads.

References

  • github.com/advisories/GHSA-5cj2-rqqf-hx9p
  • github.com/juju/juju/commit/d06919eb03ec68156818bcc304b5fe1c39a8f9e9
  • github.com/juju/juju/security/advisories/GHSA-5cj2-rqqf-hx9p
  • nvd.nist.gov/vuln/detail/CVE-2026-32694

Code Behaviors & Features

Detect and mitigate CVE-2026-32694 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.0-20221021155847-35c560704ee2 before 0.0.0-20260319091847-d06919eb03ec

Fixed versions

  • 0.0.0-20260319091847-d06919eb03ec

Solution

Upgrade to version 0.0.0-20260319091847-d06919eb03ec or above.

Impact 6.6 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-343: Predictable Value Range from Previous Values

Source file

go/github.com/juju/juju/CVE-2026-32694.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 21 May 2026 12:18:06 +0000.