Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
History

Wed, 28 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Description Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the juju controller, enabling a charm to maintain otherwise revoked or expired permissions. This allows a charm to continue relating to another charm in a cross-model relation, and use their workload without their permission. No fix is available as of the time of writing.
Weaknesses CWE-347
CWE-672
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-01-28T15:06:23.120Z

Reserved: 2026-01-20T16:56:24.051Z

Link: CVE-2026-1237

cve-icon Vulnrichment

Updated: 2026-01-28T15:06:17.121Z

cve-icon NVD

Status : Received

Published: 2026-01-28T15:16:16.363

Modified: 2026-01-28T15:16:16.363

Link: CVE-2026-1237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.