Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j477-6vpg-6c8x | Juju has broken CMR authorization |
Sat, 18 Apr 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross-Model Authorization Bypass Allowing Unauthorized Charm Interaction |
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical juju |
|
| Vendors & Products |
Canonical
Canonical juju |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing. | |
| Weaknesses | CWE-347 CWE-672 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-01-28T15:06:23.120Z
Reserved: 2026-01-20T16:56:24.051Z
Link: CVE-2026-1237
Updated: 2026-01-28T15:06:17.121Z
Status : Deferred
Published: 2026-01-28T15:16:16.363
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1237
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:45:33Z
Github GHSA