CVE-2026-32694CWE-343CWE-639

Insecure Direct Object Reference attack via predictable secret ID in Juju

Medium · published March 18, 2026

CVSS v3.1
6.6
EPSS
0%
Percentile
18.8
In the wild
Unconfirmed
What it is

In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious grantee which can request secrets to predict past secrets granted by the same secret owner to different grantees, allowing them to use the resources granted by those past secrets. Successful exploitation relies on a very specific configuration, specific data semantic, and the administrator having the need to deploy at least two different applications, one of them controlled by the attacker.

The record
Technical detail
CVSS v3.1
6.6 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00269 · 18.8th percentile
Weaknesses
CWE-343 · Predictable Value Range from Previous Values; CWE-639 · Authorization Bypass Through User-Controlled Key
Published
2026-03-18T12:55Z
EPSS history
Timeline
  • 18 MAR 12:55Z
    Insecure Direct Object Reference attack via predictable secret ID in Juju
    cvelistv5