VYPR

Virtual Lightweight Collector

by Juniper Networks

CVEs (2)

  • CVE-2026-33784CriApr 9, 2026
    risk 0.64cvss 9.8epss 0.00

    A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images ship with an initial password for a high…

  • CVE-2026-21915MedApr 9, 2026
    risk 0.44cvss 6.7epss 0.02

    A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accepts input without carefully validating it,…