CVE-2026-5774 PUBLISHED

Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map

Assigner: canonical
Reserved: 08.04.2026 Published: 10.04.2026 Updated: 10.04.2026

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.1

Product Status

Vendor Canonical
Product Juju
Versions Default: unaffected
  • affected from 2.0.0 to 2.9.57 (excl.)
  • affected from 3.0.0 to 3.6.21 (excl.)
  • affected from 4.0.0 to 4.0.6 (excl.)

References

Problem Types

  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE

Impacts

  • CAPEC-26: Leveraging Race Conditions