SB2026050818 - Privilege escalation in Junos OS Evolved
Published: May 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authentication for Critical Function (CVE-ID: CVE-2026-33788)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to gain direct access to installed flexible pic concentrators.
The vulnerability exists due to missing authentication for critical function in the flexible pic concentrators (FPCs) when handling local access by authenticated low-privileged users. A local user can gain direct access to the installed FPCs to gain direct access to installed flexible pic concentrators.
Successful exploitation provides access to the affected component as a high privileged user and can potentially lead to full compromise of that component.
Remediation
Install update from vendor's website.