---
cve: "CVE-2026-32692"
severity: "HIGH"
cvss: 7.6
epss: "17%"
vendor: "Canonical"
kev: false
exploited: false
published: "2026-03-18 13:16:18"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T12:04:01+02:00"
---

# CVE-2026-32692

> 7.6 HIGH · 🧪 PoC

## Beschreibung

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the scope of that Vault secret back-end.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- 5a261e58fcd3bd366b36229bfd1c46e6b3b61402 (Commit)

## Referenzen

- <https://github.com/juju/juju/security/advisories/GHSA-89x7-5m5m-mcmm>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-32692) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
