CVSS
No CVSS.
V
ulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
References
Configurations
No configuration.
History
28 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 15:16
Updated : 2026-01-29 16:31
NVD link : CVE-2026-1237
Mitre link : CVE-2026-1237
CVE.ORG link : CVE-2026-1237
JSON object : View
Products Affected
No product.