CVE-2025-52987

Publication date

2026-01-15 20:10:44

Family

juniper

State

PUBLISHED

Description

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the applications failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attackers control.  This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.