« Volver al listado

CVE-2026-32691

Estado: AnalizadaMedia (5.3)—

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-32691",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-32691",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-18T13:46:45.894829Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://github.com/juju/juju",
          "vendor": "Canonical",
          "product": "Juju",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.6.19",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "juju",
          "collectionURL": "https://github.com/juju/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-18T13:16:18.163",
  "references": [
    {
      "url": "https://github.com/juju/juju/security/advisories/GHSA-gfgr-6hrj-85ww",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-708"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision."
    },
    {
      "lang": "es",
      "value": "Una condición de carrera en el subsistema de gestión de secretos de las versiones de Juju 3.0.0 a 3.6.18 permite a un agente de unidad autenticado reclamar la propiedad de un secreto recién inicializado. Entre la generación de un ID de Secreto de Juju y la creación de la primera revisión del secreto, un atacante autenticado como otro agente de unidad puede reclamar la propiedad de un secreto conocido. Esto lleva a que la unidad atacante pueda leer el contenido de la revisión inicial del secreto."
    }
  ],
  "lastModified": "2026-06-17T10:36:12.903",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BAFE599-DF11-429B-9A8C-970BDB3065C8",
              "versionEndExcluding": "3.6.19",
              "versionStartIncluding": "3.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}