VendorsCanonicaljujuall versions
Vulnerabilities

Canonical Juju

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2017-9232
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
Published 2017-05-28 · Modified
10.01 PoCEPSS 0.485
CVE-2026-4370
Improper TLS Client/Server authentication and certificate verification on Database Cluster
Published 2026-04-01 · Analyzed
10.0EPSS 0.004
CVE-2026-5412
Juju CloudSpec API could leak senstive information
Published 2026-04-10 · Analyzed
9.9EPSS 0.004
CVE-2025-53513
Zip slip vulnerability in Juju
Published 2025-07-08 · Analyzed
8.8EPSS 0.007
CVE-2025-0928
Arbitrary executable upload via authenticated endpoint
Published 2025-07-08 · Analyzed
8.8EPSS 0.006
CVE-2024-6984
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
Published 2024-07-29 · Modified
8.8EPSS 0.004
CVE-2026-32693
Unauthorized access to Kubernetes secrets in Juju
Published 2026-03-18 · Analyzed
8.8EPSS 0.003
CVE-2024-7558
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same information and tools as the Juju charm.
Published 2024-10-02 · Analyzed
8.7EPSS 0.005
CVE-2024-8038
Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.
Published 2024-10-02 · Analyzed
7.9EPSS 0.002
CVE-2026-32692
Unauthorized update of out-of-scope Vault secrets
Published 2026-03-18 · Analyzed
7.6EPSS 0.002
CVE-2015-1316
Juju Joyent provider uploads user's private ssh key by default
Published 2019-04-22 · Modified
7.5EPSS 0.012
CVE-2025-68153
Juju: Resource poisoning
Published 2026-04-03 · Analyzed
7.1EPSS 0.002
CVE-2025-68152
Juju: Read All Controller Logs From Compromised Workload
Published 2026-04-03 · Analyzed
6.9EPSS 0.004
CVE-2026-32694
Insecure Direct Object Reference attack via predictable secret ID in Juju
Published 2026-03-18 · Analyzed
6.6EPSS 0.003
CVE-2025-53512
Sensitive log retrieval in Juju
Published 2025-07-08 · Analyzed
6.5EPSS 0.003
CVE-2024-8037
Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm.
Published 2024-10-02 · Analyzed
6.5EPSS 0.002
CVE-2026-5774
Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map
Published 2026-04-10 · Analyzed
6.4EPSS 0.002
CVE-2026-32691
Timing ownership claim attack on new external back-end secrets
Published 2026-03-18 · Analyzed
5.3EPSS 0.002
CVE-2023-0092
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
Published 2025-01-31 · Analyzed
4.9EPSS 0.006