Back

CRITICAL

JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access

Published Apr 9, 2026

Description

A Use of Default Password vulnerability in the Juniper Networks

Support Insights (JSI)

Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device.

vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.

Affected products

Remediation

Vendor solution

The following software releases have been updated to resolve this specific issue: 3.0.94, and all subsequent releases.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner juniper
Published Apr 9, 2026
Updated Apr 13, 2026
Reserved Mar 23, 2026
CISA Vulnrichment
Updated Apr 13, 2026
NVD
Status Analyzed
Modified Jul 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a