← Vulnerability feed

Vulnerability record · CVE-2017-9232 · published 28 May 2017

CVE-2017-9232: Juju UNIX domain socket permissions allow local privilege escalation to root

Canonical · Juju

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 creates a UNIX domain socket without appropriate permissions. Because the socket is not properly restricted, any local user on the system can interact with it and escalate privileges to root.

9.8 CVSS 3.0 Critical EPSS 49% · top 1.2% CWE-862 · Missing authorization
9.8CVSS 3.0 base score, v2 10.0
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityLocal privilege escalation to root with public exploit code and very high EPSS, though it requires an existing local foothold and is not in KEV.

What it is

Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 creates a UNIX domain socket without appropriate permissions. Because the socket is not properly restricted, any local user on the system can interact with it and escalate privileges to root.

Impact

A local unprivileged user gains root-level control of the host running Juju, allowing full compromise of the machine and any workloads or credentials it manages.

Attack surface

The flaw is reached through a local UNIX domain socket on the Juju host; no network access is required, and no authentication or user interaction beyond local access to the system is needed.

Exploitation

No CISA KEV listing, but EPSS is 0.485 (98.8th percentile) and references include an Exploit-tagged Launchpad bug and an Exploit-DB entry, indicating public exploit code exists.

What to do

  • Upgrade Juju to 1.25.12, 2.0.4, 2.1.3 or later as applicable to your release line.
  • Restrict filesystem permissions on the Juju UNIX domain socket so only the Juju service account can access it.
  • Limit interactive shell access on hosts running Juju to trusted administrators only.
  • Audit Juju-managed hosts for unexpected local accounts or privilege changes after exposure.

Detection

  • Monitor for local processes connecting to the Juju UNIX domain socket outside the expected Juju service account.
  • Alert on unexpected root-level process creation or privilege changes on Juju hosts.
  • Review file permission changes on the Juju socket path and related directories.
  • Correlate local authentication and sudo/su activity with Juju socket access on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9232 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-4370Canonical juju improper certificate validation vulnerabilityA vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…EPSS 0.41%8.8CVE-2026-32693Canonical juju improper access control vulnerabilityIn Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update th…EPSS 0.44%8.8CVE-2025-0928Canonical juju improper authorization vulnerabilityIn Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c…EPSS 0.58%8.0CVE-2024-7558Canonical juju vulnerabilityJUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged u…EPSS 0.50%7.5CVE-2015-1316Canonical juju vulnerabilityJuju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.EPSS 1.2%7.1CVE-2025-68153Canonical juju incorrect authorization vulnerabilityJuju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope…EPSS 0.23%6.9CVE-2025-68152Canonical juju incorrect authorization vulnerabilityJuju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special ope…EPSS 0.36%6.6CVE-2026-32694Canonical juju insecure direct object reference vulnerabilityIn Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2017-9232), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.