CVE-2026-5412
Critical Severity
Description
In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method ...
Related Vulnerabilities
- CVE-2026-40175: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain CRITICAL
- CVE-2026-4432: The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist own HIGH
- CVE-2026-35655: OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution t MEDIUM
- CVE-2026-5981: A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall HIGH
- CVE-2026-5483: A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` HIGH
Related Coverage
Threat Actors