Improper Following of a Certificate's Chain of Trust in Junos OS - CVE-2026-33779

 

Improper Following of a Certificate's Chain of Trust in Junos OS - CVE-2026-33779

Published: May 8, 2026


Vulnerability identifier: #VU130690
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33779
CWE-ID: CWE-296
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and potentially modify it.

The vulnerability exists due to improper following of a certificate's chain of trust in J-Web when an SRX device is provisioned to connect to Security Director cloud. A remote attacker can intercept device-to-cloud communication using a machine-in-the-middle position to disclose sensitive information and potentially modify it.

The issue affects communication between SRX devices and Security Director cloud, and exposed data may include credentials.


Affected software

Junos OS

How to mitigate CVE-2026-33779

Install security update from vendor's website.

Junos OS - addressed in versions 22.4R3-S9, 23.2R2-S6, 23.4R2-S7, 24.2R2-S3, 24.4R2-S2, 25.2R1-S2, 25.2R2, 25.4R1

External References

Related Security Bulletins