GHSA-w5fq-8965-c969 · Severity: critical · Ecosystem: go — Juju: CloudSpec method leaking cloud credentials
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.
Conclusion & alert: CVE-2026-5412 is rated Exploit Available (58.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-11 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-w5fq-8965-c969 · Severity: critical · Ecosystem: go — Juju: CloudSpec method leaking cloud credentials
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2026-5412 medium priority: Ubuntu including 1 source packages (juju), 4 status rows across 4 suites (jammy, noble, questing, upstream): DNE 3, needs-triage 1. | https://ubuntu.com/security/CVE-2026-5412 |
| URL | Tags |
|---|---|
| https://github.com/juju/juju/pull/22205 | Issue Tracking Patch |
| https://github.com/juju/juju/pull/22206 | Issue Tracking Patch |
| https://github.com/juju/juju/security/advisories/GHSA-w5fq-8965-c969 | Exploit Third Party Advisory |