CVE-2026-5774

Severity CVSS v4.0:
MEDIUM
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
10/04/2026
Last modified:
22/04/2026

Description

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* 2.9.57 (excluding)
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* 3.0 (including) 3.6.21 (excluding)
cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* 4.0 (including) 4.0.6 (excluding)