Junglewise Threat Intelligence

CVE-2026-21901: Juniper Networks Junos OS NULL pointer dereference in mgd

CVE-2026-21901 · Severity: medium · CVSS 4.4 · Published 2026-07-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks' Junos OS management software allows a high-privileged user to crash the management system by applying or removing a specific SSH configuration setting. This results in a denial-of-service condition that prevents administrators from managing the device. While it requires high-level access to exploit, repeated attempts can cause sustained instability of the management interface.

Technical details

A NULL pointer dereference vulnerability exists in the management daemon (mgd) of Junos OS and Junos OS Evolved, specifically within the auth_principals_validate_comm() function in libjunos-actions-impl.so. The flaw is triggered when a high-privileged local user configures or deactivates the 'system services ssh authorized-principals-command' parameter. The function fails to validate configuration data pointers before dereferencing them, leading to a SIGSEGV and subsequent crash of the mgd process. While the primary impact is Denial of Service (DoS) of the management plane, some researchers suggest potential for privilege escalation given mgd runs with root privileges. Fixed versions include Junos OS 22.3R3-S5, 22.4R3-S10, 23.2R2-S7, 23.4R2-S8, and 24.2R1.

Affected products

  • Juniper Networks Junos OS 22.3 before 22.3R3-S5, 22.4 before 22.4R3-S10, 23.2 before 23.2R2-S7, 23.4 before 23.4R2-S8
  • Juniper Networks Junos OS Evolved 22.3R1-EVO before 23.2R2-S7-EVO, 23.4 before 23.4R2-S8-EVO

Timeline

  • 2025-11-10: disclosed: Reported to vendor by Orange CERT-CC
  • 2026-07-08: patched
  • 2026-07-09: advisory

References

Related threats