VulnerabilityAnalyzed
CVE-2026-5774
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
MEDIUM 6.0EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
- CVSS 4.0
- 6.0 MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- canonical/juju
- Source
- security@ubuntu.com
References
- https://github.com/juju/juju/pull/22205Issue Tracking
- https://github.com/juju/juju/pull/22206Issue Tracking
- https://github.com/juju/juju/security/advisories/GHSA-7m55-2hr4-pw78Exploit, Third Party Advisory
- https://github.com/juju/juju/security/advisories/GHSA-7m55-2hr4-pw78Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.