CVE-2026-5412
Critical Severity
Description
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method ...
Related Vulnerabilities
- CVE-2026-34424: Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access to CRITICAL
- CVE-2026-5187: Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. LOW
- CVE-2026-35649: OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to MEDIUM
- CVE-2026-35600: Vikunja has HTML Injection via Task Titles in Overdue Email Notifications MEDIUM
- CVE-2026-40162: Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability wa HIGH
Related Coverage
Threat Actors