CVE-2026-33784 Details
Description
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.
A vulnerability allowing unauthorized high-privileged access has been identified in all versions of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) prior to 3.0.94. This vulnerability arises from the software being shipped with a default password for a high-privileged account, which is not required to be changed during the initial setup. As a result, an unauthenticated, network-based attacker could gain full control of the device.
Users can change the default password in the setup menu of the device. Instructions for configuring network settings through the JSI shell are available on the Juniper Networks documentation site. Additionally, updating to vLWC version 3.0.94 or later will resolve this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107871 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-1393 | Use of Default Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper virtual lightweight collector | < 3.0.94 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |