Executive brief
A race condition in the Canonical Juju API server's token management allows authenticated users to cause a denial of service or reuse single-use discharge tokens.
Affected products
- Go github.com/juju/juju
Junglewise Threat Intelligence
CVE-2026-5774 · Severity: medium · CVSS 6.4 · Published 2026-04-10
Technologies: github.com/juju/juju (Go). Vendors: Go.
A race condition in the Canonical Juju API server's token management allows authenticated users to cause a denial of service or reuse single-use discharge tokens.