Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 10 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 12:30:00 +0000

Type Values Removed Values Added
Description Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
Title Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map
Weaknesses CWE-362
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-04-10T12:41:28.720Z

Reserved: 2026-04-08T07:22:06.115Z

Link: CVE-2026-5774

cve-icon Vulnrichment

Updated: 2026-04-10T12:41:02.565Z

cve-icon NVD

Status : Received

Published: 2026-04-10T13:16:46.070

Modified: 2026-04-10T13:16:46.070

Link: CVE-2026-5774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses