CVE-2026-33784 is a critical use of default password vulnerability affecting Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) software versions prior to 3.0.94. The vLWC ships with a default high-privileged account password that is not enforced to be changed during initial provisioning, allowing unauthorized actors to obtain full administrative access to affected devices. The vulnerability carries a CVSS score of 9.8 (Critical) and can be exploited by unauthenticated network-based attackers with no special privileges or user interaction required. The attack vector is network-based with low complexity, and successful exploitation results in complete compromise of system confidentiality, integrity, and availability. There is currently no evidence of active exploitation in the wild, and this vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. The EPSS probability score of 0.00054 indicates relatively low probability of exploitation compared to the broader CVE landscape, and community attention remains inactive at this time. Organizations running affected vLWC versions should prioritize upgrading to version 3.0.94 or later and immediately change all default credentials as an interim measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.94CPE matchmatch criteria | cpe:2.3:a:juniper:virtual_lightweight_collector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.