Execution with unnecessary privileges in Junos OS and Junos OS Evolved - CVE-2026-33793

 

Execution with unnecessary privileges in Junos OS and Junos OS Evolved - CVE-2026-33793

Published: May 8, 2026


Vulnerability identifier: #VU130697
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33793
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to execution with unnecessary privileges in the User Interface (UI) when an unsigned Python op script configuration is present and Python3 op scripts are enabled. A local user can execute a malicious op script to escalate privileges.

Only systems with remote Python3 op scripts enabled are vulnerable.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2026-33793

Install security update from vendor's website.

Junos OS - addressed in versions 22.4R3-S7, 23.2R2-S4, 23.4R2-S6, 24.2R1-S2, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1
Junos OS Evolved - addressed in versions 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO

External References

Related Security Bulletins