---
id: CVE-2026-33784
title: >-
  A Use of Default Password vulnerability in the Juniper Networks 


  Support Insights (JSI) 


  Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based
  attacker to take full control of the device.


  vLWC software images s…
summary: >-
  A Use of Default Password vulnerability in the Juniper Networks 


  Support Insights (JSI) 


  Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based
  attacker to take full control of the device.


  vLWC software images s…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1393
vendor: juniper
product: virtual_lightweight_collector
affected:
  - virtual_lightweight_collector < 3.0.94
patched:
  - virtual_lightweight_collector 3.0.94
published: '2026-04-09'
updated: '2026-07-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33784'
references:
  - url: 'https://kb.juniper.net/JSA107871'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.00483
epssPercentile: 0.38942
ingestedAt: '2026-07-08T03:46:38.637Z'
---

## Overview

A Use of Default Password vulnerability in the Juniper Networks 

Support Insights (JSI) 

Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device.

vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full access to the system by unauthorized actors possible.This issue affects all versions of vLWC before 3.0.94.

## Affected

- `virtual_lightweight_collector < 3.0.94`

## Remediation

Upgrade past the affected range:

- `virtual_lightweight_collector 3.0.94`
