CVE-2026-5774

Publication date 13 April 2026

Last updated 13 April 2026


Ubuntu priority

Description

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

Status

Package Ubuntu Release Status
juju 25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release


Access our resources on patching vulnerabilities