CVE-2026-1237 - Juju Charm Cross-Model Authorization Bypass
CVE ID : CVE-2026-1237
Published : Jan. 28, 2026, 3:16 p.m. | 1 hour, 43 minutes ago
Description : Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 28, 2026, 3:16 p.m. | 1 hour, 43 minutes ago
Description : Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...