Back to overview

CVE-2026-4370

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once joined, the attacker gains full read and write access to the underlying database, allowing for total data compromise.

Metadata

CVE ID
CVE-2026-4370
State
PUBLISHED
Assigner
canonical
Reserved
2026-03-18 08:46 UTC
Published
2026-04-01 08:09 UTC
Last updated
2026-04-08 07:27 UTC
Primary CWE
CWE-295
CWE-295 Improper certificate validation
Vendor / Product
Canonical / Juju
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Canonical Juju Linux 3.2.0 < 3.6.20, 4.0 < 4.0.4
Weakness (CWE)
CWESourceDescription
CWE-295 cna CWE-295 Improper certificate validation
CWE-306 cna CWE-306 Missing authentication for critical function
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview