CVE-2026-32693
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.
- Affected products
- Juju, Kubernetes
- Canonical Juju
- < 3.6.19
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.3% (23th percentile)
- Weakness
- CWE-778, CWE-863, CWE-284
- NVD status
- Analyzed
- Published
- 2026-03-18
- Attack patterns
- CAPEC-124
CVE-2026-32693 at NVD
No indexed exploits for CVE-2026-32693 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-32693 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.