cbcvebase.
CVE-2026-33793
published 2026-04-09

CVE-2026-33793: An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local…

high8.5CVSS 4.0
AVLACLATNPRLUINVCHVIHVAHSCNSINSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation. This issue affects Junos OS: * All versions before 22.4R3-S7, * from 23.2 before 23.2R2-S4, * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R1-S2, 24.2R2, * from 24.4 before 24.4R1-S2, 24.4R2; Junos OS Evolved: * All versions before 22.4R3-S7-EVO, * from 23.2 before 23.2R2-S4-EVO, * from 23.4 before 23.4R2-S6-EVO, * from 24.2 before 24.2R2-EVO, * from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

Affected

11 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniper_networksjunos_os< 22.4R3-S722.4R3-S7
juniper_networksjunos_os>= 23.2 < 23.2R2-S423.2R2-S4
juniper_networksjunos_os>= 23.4 < 23.4R2-S623.4R2-S6
juniper_networksjunos_os>= 24.2 < 24.2R1-S2, 24.2R224.2R1-S2, 24.2R2
juniper_networksjunos_os>= 24.4 < 24.4R1-S2, 24.4R224.4R1-S2, 24.4R2
juniper_networksjunos_os_evolved< 22.4R3-S7-EVO22.4R3-S7-EVO
juniper_networksjunos_os_evolved>= 23.2 < 23.2R2-S4-EVO23.2R2-S4-EVO
juniper_networksjunos_os_evolved>= 23.4 < 23.4R2-S6-EVO23.4R2-S6-EVO
juniper_networksjunos_os_evolved>= 24.2 < 24.2R2-EVO24.2R2-EVO
juniper_networksjunos_os_evolved>= 24.4 < 24.4R1-S1-EVO, 24.4R2-EVO24.4R1-S1-EVO, 24.4R2-EVO