SB2026050824 - Privilege escalation in Junos OS and Junos OS Evolved
Published: May 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Execution with unnecessary privileges (CVE-ID: CVE-2026-33793)
CWE-ID: CWE-250 - Execution with Unnecessary Privileges
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to execution with unnecessary privileges in the User Interface (UI) when an unsigned Python op script configuration is present and Python3 op scripts are enabled. A local user can execute a malicious op script to escalate privileges.
Only systems with remote Python3 op scripts enabled are vulnerable.
Remediation
Install update from vendor's website.