Home

Description

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation. This issue affects Junos OS: * All versions before 22.4R3-S7, * from 23.2 before 23.2R2-S4, * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R1-S2, 24.2R2, * from 24.4 before 24.4R1-S2, 24.4R2; Junos OS Evolved: * All versions before 22.4R3-S7-EVO, * from 23.2 before 23.2R2-S4-EVO, * from 23.4 before 23.4R2-S6-EVO, * from 24.2 before 24.2R2-EVO, * from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

PUBLISHED Reserved 2026-03-23 | Published 2026-04-09 | Updated 2026-04-16 | Assigner juniper




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Amber

Problem types

CWE-250: Execution with Unnecessary Privileges

Product status

Default status
unaffected

Any version before 22.4R3-S7
affected

23.2 (semver) before 23.2R2-S4
affected

23.4 (semver) before 23.4R2-S6
affected

24.2 (semver) before 24.2R1-S2, 24.2R2
affected

24.4 (semver) before 24.4R1-S2, 24.4R2
affected

Default status
unaffected

Any version before 22.4R3-S7-EVO
affected

23.2 (semver) before 23.2R2-S4-EVO
affected

23.4 (semver) before 23.4R2-S6-EVO
affected

24.2 (semver) before 24.2R2-EVO
affected

24.4 (semver) before 24.4R1-S1-EVO, 24.4R2-EVO
affected

Timeline

2026-04-08:Initial Publication
2026-04-16:While 'language python3' allows an attacker to execute local Python scripts, the scenario with the highest risk of malicious exploitation occurs when an attacker can execute remote Python scripts

References

supportportal.juniper.net/JSA103142 vendor-advisory

cve.org (CVE-2026-33793)

nvd.nist.gov (CVE-2026-33793)

Download JSON