Junglewise Threat Intelligence

CVE-2025-68152: Canonical Juju Incorrect Authorization in Debug Log Endpoint

CVE-2025-68152 · Severity: medium · CVSS 4.9 · Published 2026-04-03

Technologies: Canonical Juju, github.com/juju/juju (Go). Vendors: Canonical, Go.

Executive brief

Juju is an application orchestration engine used to deploy and manage software across various cloud infrastructures. A security flaw allows a compromised machine within the environment to access sensitive log files from across the entire management system. This could lead to the exposure of administrative secrets or operational data, potentially facilitating further attacks on the infrastructure.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Juju API server's debug log endpoint. While the endpoint requires authentication, it fails to properly restrict machine agents to their own logs, allowing a compromised workload machine to use its credentials to stream logs for any entity, model, or the controller itself at any log level. This can result in the exposure of sensitive information leaked in debug or trace logs. The issue is fixed in Juju versions 2.9.56 and 3.6.19 by ensuring the authorizer correctly validates model-level permissions.

Affected products

  • Canonical Juju 2.9 to 2.9.55, 3.6 to 3.6.18

Timeline

  • 2026-04-01: advisory: Vendor advisory published on GitHub
  • 2026-04-03: disclosed: CVE published to NVD
  • 2026-04-03: patched: Patches released in versions 2.9.56 and 3.6.19

References

Related threats