CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-5412

CVE-2026-5412: Broken Access Control in Juju API Leads to Cloud Credential Leak

Alon Barad
Alon Barad
Software Engineer

Apr 11, 2026·7 min read·89 visits

Executive Summary (TL;DR)

Authenticated attackers can exploit missing access controls in Juju's CloudSpec API method to retrieve plaintext cloud provider credentials, granting them full control over the host infrastructure.

CVE-2026-5412 is a critical improper authorization vulnerability within the Canonical Juju API server. Low-privileged authenticated users can bypass authorization controls via the Controller facade to extract plaintext bootstrap cloud credentials, leading to total compromise of the underlying cloud environment.

Vulnerability Overview

Juju operates as a model-driven operator lifecycle manager, coordinating application deployments across various cloud environments. The Juju API server facilitates remote management by exposing functionality through specific interfaces called facades. These facades are accessed via a JSON-RPC interface, typically bound to TCP port 17070 on the controller node.

The vulnerable component resides within the Controller facade, specifically within the CloudSpec method implementation. This method returns operational and configuration details about the specific cloud environment currently managed by the controller. Clients routinely query this endpoint to retrieve connection metadata and regional configuration states.

The vulnerability is formally classified as CWE-285: Improper Authorization. The core issue lies in the system's failure to enforce role-based access control (RBAC) constraints on the data returned by the CloudSpec method. The system relies entirely on basic authentication and possession of a model identifier, failing to verify administrative privileges.

The Common Vulnerability Scoring System (CVSS v3.1) evaluates this flaw at 9.9 out of 10.0. The score reflects the critical nature of the vulnerability: it requires no user interaction, operates over the network, requires only low-level privileges, and completely alters the scope of the attack by compromising the independent cloud infrastructure.

Root Cause Analysis

The root cause is a failure to enforce functional-level access controls within the Juju RPC request pipeline prior to object serialization. The CloudSpec method accepts a model UUID as its primary argument and retrieves the corresponding cloud specification from the state database. The method processes this request uniformly for all authenticated users.

Prior to the patch, the application logic only verified two conditions: the client established a valid authentication session, and the supplied model UUID existed within the system. The controller lacked explicit validation checks to determine if the requesting user held administrative rights over the requested model. The system trusted the client application to request only the data it was permitted to view.

The database returns a CloudSpec object containing several fields, including the sensitive Credential attribute. This specific field stores the plaintext secrets required to interact with the cloud provider API. Depending on the environment, this field contains AWS IAM keys, Azure service principal secrets, or OpenStack credentials used during the initial controller bootstrap.

Because the API server serializes the complete CloudSpec object without applying context-aware data filtering, the sensitive payload is transmitted across the network to the requesting client. Any user with a baseline login permission on the controller receives the unredacted data structure, bypassing intended authorization boundaries.

Code Analysis and Patch Walkthrough

Canonical addressed the vulnerability via pull request 22206, modifying the core authorization logic within apiserver/common/cloudspec/cloudspec.go. The developers introduced a data redaction phase immediately preceding the API response serialization. The patch inspects the caller's identity and permissions dynamically.

The implementation utilizes a two-tier authorization model to distinguish between internal agents and external users. The server evaluates the request context to identify the caller's source. Internal system components, such as Controller Agents or Model Agents, and users holding the global Superuser role bypass the granular checks and receive the full data structure.

For standard user clients, the patch introduces a systematic iteration over the requested model entities. The code invokes an explicit AdminAccess authorization check for each individual model. This function queries the access control list to verify that the specific authenticated user possesses administrative rights for the target UUID.

When the AdminAccess check fails, the application executes a structural redaction. The patch explicitly nullifies the Credential field by assigning it a nil value within the memory structure.

Exploitation Methodology

Exploitation begins with network access to the Juju controller API, operating on TCP port 17070. The attacker must possess valid credentials for an account provisioned on the controller. The specific privilege level of this account is irrelevant; minimal login access satisfies the vulnerability's prerequisites.

The attacker initiates a standard JSON-RPC session using the acquired credentials. Following authentication, the attacker requires the target controller's model UUID to construct the subsequent payload. This identifier is frequently exposed through unauthenticated or low-privileged metadata endpoints within the Juju discovery API.

With the model UUID confirmed, the attacker constructs a direct RPC call to the Controller facade. The payload invokes the CloudSpec method, passing the discovered model UUID as the target parameter. The attacker submits this carefully formatted JSON payload through the established authenticated socket.

The API server processes the request and responds with a JSON object encompassing the complete cloud specification. The attacker parses this response to isolate the Credential block. The extracted plaintext string immediately grants the attacker the underlying cloud provider API access rights, completing the exploit chain.

Impact Assessment

The security impact extends completely beyond the Juju controller ecosystem to the underlying cloud infrastructure provider. The leaked bootstrap credentials possess extensive administrative permissions by design, as they must manage compute instances, storage volumes, and network security policies required by the Juju application.

An attacker extracting these credentials gains unconstrained control over the target cloud environment via the provider's standard APIs (e.g., AWS CLI, Azure Resource Manager). They can provision unauthorized infrastructure, delete critical production databases, or alter network configurations to expose internal services to the public internet.

The CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H precisely maps this structural boundary violation. The critical "Scope: Changed" (S:C) metric indicates that a vulnerability within the Juju software directly compromises the functionally distinct cloud infrastructure layer. The impacts to Confidentiality, Integrity, and Availability are uniformly High.

The attack profile presents high risk due to its low operational complexity. Exploitation relies on standard API requests and requires no specific memory corruption vectors or timing techniques. Attackers can fully automate the extraction process and integrate the technique into standard post-exploitation toolkits.

Remediation and Mitigation

Administrators must immediately upgrade affected Juju controller deployments to version 2.9.57 or 3.6.21. These patched releases integrate the mandatory access control enforcement mechanisms required to protect the CloudSpec endpoint. System operators should utilize standard Juju upgrade procedures to apply the new binaries across their fleets.

Software updates block future unauthorized access but provide no remediation for prior credential exposure. Administrators must operate under the assumption that the controller's bootstrap cloud credentials were compromised if untrusted users maintained login access to the vulnerable versions.

Security teams must execute an immediate cryptographic rotation of the affected cloud provider credentials. This process involves generating new IAM keys, service principals, or API tokens within the cloud provider console, updating the Juju controller with the new secrets, and permanently revoking the previous credentials.

Organizations must systematically apply the principle of least privilege across their Juju deployments. Administrators must audit controller user accounts and aggressively prune unnecessary login permissions. Access to the controller API must be restricted at the network level, utilizing strict firewalls or zero-trust overlays to permit connections only from authorized administration subnets.

Official Patches

GitHub AdvisoryOfficial Security Advisory
CanonicalFix pull request for CloudSpec API

Fix Analysis (2)

Technical Appendix

CVSS Score
9.9/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Systems

Canonical Juju 2.9.x before 2.9.57Canonical Juju 3.6.x before 3.6.21AWS, Azure, OpenStack, and GCP environments managed by vulnerable Juju controllers

Affected Versions Detail

Product
Affected Versions
Fixed Version
Juju
Canonical
>= 2.9.0, < 2.9.572.9.57
Juju
Canonical
>= 3.6.0, < 3.6.213.6.21
AttributeDetail
CWE IDCWE-285
CVSS Score9.9
Attack VectorNetwork
Privileges RequiredLow
ScopeChanged
Exploit MaturityPoC

MITRE ATT&CK Mapping

T1552Unsecured Credentials
Credential Access
CWE-285
Improper Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Vulnerability Timeline

Initial patch for a related data race in the login handler (PR #22205)
2026-03-20
Main authorization fix for CloudSpec API committed (PR #22206)
2026-04-02
CVE-2026-5412 published and GHSA-w5fq-8965-c969 released
2026-04-10

References & Sources

  • [1]NVD - CVE-2026-5412
  • [2]GitHub Advisory GHSA-w5fq-8965-c969
  • [3]Juju Pull Request 22205
  • [4]Juju Pull Request 22206

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•21 minutes ago•CVE-2026-92945
4.2

CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

A module allowlist bypass vulnerability (CVE-2026-92945 / GHSA-7q3f-wx44-378m) was identified in the vm2 sandboxing library prior to version 3.11.7. This flaw permits unauthenticated or untrusted code running within the sandbox environment to bypass explicit module restrictions. When the transitive resolution option is disabled, the system fails to validate file system path boundaries, allowing prefix-sharing sibling directories to be resolved and loaded, thereby escaping intended sandbox restrictions.

Amit Schendel
Amit Schendel
2 views•6 min read
•about 1 hour ago•CVE-2026-92941
10.0

CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

CVE-2026-92941 is a critical sandbox-escape and trust-manipulation vulnerability in the vm2 library (versions 3.11.3 to 3.11.6). This security flaw allows untrusted code executing within a NodeVM sandbox environment to compromise the global TLS trust store of the host Node.js process. By leveraging a design flaw where the host's native 'tls.setDefaultCACertificates' can be executed via a proxy wrapper, combined with a bridge unwrapping bypass in the 'url' module, an attacker can modify the process-wide default root Certificate Authorities. Consequently, all subsequent outbound TLS/HTTPS clients running on the host thread are forced to trust attacker-signed certificates, facilitating transparent Man-in-the-Middle (MitM) attacks. The vulnerability was resolved in version 3.11.7 of vm2 by introducing built-in member-level sanitization before applying read-only proxy wrappers.

Amit Schendel
Amit Schendel
2 views•10 min read
•about 2 hours ago•CVE-2026-92944
9.8

CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

A critical engine-level reachability failure in Node.js 26 running V8 14.6 allows attackers to escape the vm2 sandbox environment. When consecutive prototype properties are modified using sequential assignments, a V8 optimization bug fails to invalidate the PromiseThenLookupChain protector. By calling Promise.prototype.finally, the attacker bypasses the vm2 wrappers, hijacks the promise reaction using a custom constructor, triggers a calibrated stack overflow to capture a host-realm RangeError, and executes arbitrary shell commands on the host.

Alon Barad
Alon Barad
3 views•8 min read
•about 3 hours ago•CVE-2026-92939
9.9

CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

A critical sandbox escape vulnerability in the vm2 library allows sandboxed JavaScript code to bypass containment and execute arbitrary native code on the host process. This occurs when the host's builtin crypto module is exposed to the NodeVM environment. Although vm2 implements a read-only proxy layer to restrict direct modifications to host properties, it does not prevent invocation of host-level functions. By calling the crypto.setEngine API with a path to a malicious native library on disk, an attacker can trigger OpenSSL's dynamic module loader. The host's operating system loader immediately runs the dynamic library's initializers/constructors before verifying engine compatibility, leading to remote code execution in the context of the host process.

Amit Schendel
Amit Schendel
4 views•5 min read
•about 4 hours ago•CVE-2026-92938
9.9

CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 5 hours ago•CVE-2026-92937
10.0

CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937 is a critical sandbox escape vulnerability in the `vm2` Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using `Function.prototype.call` or `Function.prototype.apply` indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.

Amit Schendel
Amit Schendel
6 views•6 min read