SB2026050818 - Privilege escalation in Junos OS Evolved



SB2026050818 - Privilege escalation in Junos OS Evolved

Published: May 8, 2026

Security Bulletin ID SB2026050818
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authentication for Critical Function (CVE-ID: CVE-2026-33788)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to gain direct access to installed flexible pic concentrators.

The vulnerability exists due to missing authentication for critical function in the flexible pic concentrators (FPCs) when handling local access by authenticated low-privileged users. A local user can gain direct access to the installed FPCs to gain direct access to installed flexible pic concentrators.

Successful exploitation provides access to the affected component as a high privileged user and can potentially lead to full compromise of that component.


Remediation

Install update from vendor's website.