CVE-2026-5412
Critical Severity
Description
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method ...
Related Vulnerabilities
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-34478: Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424L MEDIUM
- CVE-2026-2712: The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to mi MEDIUM
- CVE-2025-14545: The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via CRITICAL
- CVE-2026-34983: Wasmtime has use-after-free bug after cloning `wasmtime::Linker` MEDIUM
Related Coverage
Threat Actors