6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control.
This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.
This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.
Basic Information
ID
CVE-2025-52987
Source
juniper
Published
Jan 15, 2026 at 20:10
Affected Product
Vendor
Juniper Networks
Product
Paragon Automation (Pathfinder, Planner, Insights)
Affected Versions
Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) 0