GHSA-gvrj-cjch-728p · Severity: critical · Ecosystem: go — Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.
Conclusion & alert: CVE-2026-4370 is rated High Exploit Risk (65.7/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.38%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.38% | +0.33% |
| 2 | 2026-06-08 | 0.03% | 0.05% | +0.02% |
| 3 | 2026-04-21 | — | 0.03% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
GHSA-gvrj-cjch-728p · Severity: critical · Ecosystem: go — Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
critical | CVE-2026-4370 critical priority: Ubuntu including 1 source packages (juju), 4 status rows across 4 suites (jammy, noble, questing, upstream): DNE 3, needs-triage 1. | https://ubuntu.com/security/CVE-2026-4370 |
| URL | Tags |
|---|---|
| https://github.com/juju/juju/security/advisories/GHSA-gvrj-cjch-728p | Exploit Vendor Advisory |