SB2026050824 - Privilege escalation in Junos OS and Junos OS Evolved



SB2026050824 - Privilege escalation in Junos OS and Junos OS Evolved

Published: May 8, 2026

Security Bulletin ID SB2026050824
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Execution with unnecessary privileges (CVE-ID: CVE-2026-33793)

CWE-ID: CWE-250 - Execution with Unnecessary Privileges

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to execution with unnecessary privileges in the User Interface (UI) when an unsigned Python op script configuration is present and Python3 op scripts are enabled. A local user can execute a malicious op script to escalate privileges.

Only systems with remote Python3 op scripts enabled are vulnerable.


Remediation

Install update from vendor's website.