CVE-2026-21916: Junos OS: A low privileged user can escalate their privileges so that they can login as root
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system.
When after a user has performed a specific 'file link ...' CLI operation, another user commits (unrelated configuration changes), the first user can login as root.
This issue affects Junos OS: all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S2, 25.2 versions before 25.2R2.
This issue does not affect versions 25.4R1 or later.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21916?
CVE-2026-21916 is considered a high severity vulnerability due to its potential for privilege escalation to root.
How do I fix CVE-2026-21916?
To fix CVE-2026-21916, upgrade your Junos OS to a version that is not affected by this vulnerability.
Who is affected by CVE-2026-21916?
CVE-2026-21916 affects local, authenticated users with low privileges on specific versions of Junos OS.
What can an attacker achieve with CVE-2026-21916?
An attacker can escalate their privileges to root, potentially gaining full control over the system.
What versions of Junos OS are impacted by CVE-2026-21916?
CVE-2026-21916 affects Junos OS versions up to but not including 23.2R2-S7, 23.4R2-S6, 24.2R2-S3, 24.4R2-S2, and 25.2R2.