CVE-2026-33784: JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
A Use of Default Password vulnerability in the Juniper Networks
Support Insights (JSI)
Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device.
vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks vLWCto a version that resolves this vulnerability.Fixed in 3.0.94 - Operational
After provisioning/upgrading, change the initial default password for the high-privileged account shipped in vLWC images; do not rely on the shipped initial password.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33784?
CVE-2026-33784 is classified as a critical severity vulnerability due to unauthorized high-privileged access arising from the use of default passwords.
How do I fix CVE-2026-33784?
To mitigate CVE-2026-33784, change the default password in the Juniper Networks JSI Virtual Lightweight Collector to a strong, unique password.
Who is affected by CVE-2026-33784?
CVE-2026-33784 affects users of the Juniper Networks JSI Virtual Lightweight Collector version up to 3.0.94 that have not changed the default password.
What type of vulnerability is CVE-2026-33784?
CVE-2026-33784 is a Use of Default Password vulnerability that allows unauthenticated access to the system.
What impact could CVE-2026-33784 have?
The impact of CVE-2026-33784 includes unauthorized access and potential manipulation of sensitive network configurations and data.