Use After Free Vulnerability in Junos OS and Junos OS Evolved by Juniper Networks
CVE-2026-21921
7.1HIGH
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
👾 Exploit Exists
What is CVE-2026-21921?
A Use After Free vulnerability exists in the chassis daemon of Juniper Networks' Junos OS and Junos OS Evolved. This flaw permits an attacker with low privileges to initiate a Denial-of-Service condition. Under certain conditions, particularly when telemetry collectors continually subscribe and unsubscribe to sensors over an extended duration, critical telemetry processes such as chassisd, rpd, or mib2d may crash and require a restart. This behavior can lead to significant outages, disrupting system operations until recovery is complete.
Affected Version(s)
Junos OS 0 < 22.4R3-S8
Junos OS 23.2 < 23.2R2-S5
Junos OS 23.4 < 23.4R2