Junglewise Threat Intelligence

CVE-2026-21915: Juniper Networks JSI vLWC privilege escalation in CLI

CVE-2026-21915 · Severity: medium · CVSS 6.7 · Published 2026-04-09

Vendors: Juniper, Juniper Networks.

Executive brief

A security vulnerability exists in Juniper Networks Support Insights (JSI) Virtual Lightweight Collector, a tool used for network monitoring and data collection. A local attacker with high-level administrative access can bypass security restrictions to gain full root control over the system. This could allow an attacker to completely compromise the device, potentially leading to data theft or disruption of network monitoring operations.

Technical details

A Permissive List of Allowed Input vulnerability (CWE-183) exists in the Command Line Interface (CLI) of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC). The CLI menu fails to properly validate user input, leading to an OS command injection vulnerability (CWE-78). A local attacker who already possesses high-privileged access can exploit this flaw to execute shell commands with root permissions. Successful exploitation results in complete system compromise. The issue is resolved in version 3.0.94 and all subsequent releases.

Affected products

  • Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) All versions before 3.0.94

Timeline

  • 2026-04-09: advisory: Initial advisory published by Juniper Networks
  • 2026-04-09: disclosed

References

Related threats