PT-2026-31745 · Juniper Networks · Junos
Published
2026-04-09
·
Updated
2026-04-09
·
CVE-2026-21916
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos OS versions prior to 23.2R2-S7
Juniper Networks Junos OS versions 23.4 before 23.4R2-S6
Juniper Networks Junos OS versions 24.2 before 24.2R2-S3
Juniper Networks Junos OS versions 24.4 before 24.4R2-S2
Juniper Networks Junos OS versions 25.2 before 25.2R2
Description
A UNIX Symbolic Link (Symlink) Following vulnerability exists in the Command Line Interface (CLI) of Juniper Networks Junos OS. A local, authenticated attacker with low privileges can escalate their privileges to root, potentially leading to a complete system compromise. This occurs when a user performs a 'file link' operation via the CLI, and another user subsequently commits unrelated configuration changes. The first user can then log in as root.
Recommendations
Update to Junos OS version 23.2R2-S7 or later.
Update to Junos OS version 23.4R2-S6 or later.
Update to Junos OS version 24.2R2-S3 or later.
Update to Junos OS version 24.4R2-S2 or later.
Update to Junos OS version 25.2R2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos