CVE-2026-33793

7.8

Juniper Networks · Junos OS and Junos OS Evolved

A privilege escalation vulnerability in Juniper Networks Junos OS allows local, low-privileged users to execute unauthorized op scripts with root-level permissions, leading to full system compromise.

Executive summary

A critical privilege escalation flaw in Juniper Networks Junos OS and Junos OS Evolved allows local attackers to gain root-level access if unsigned Python op scripts are enabled.

Vulnerability

This is an Execution with Unnecessary Privileges (CWE-250) vulnerability. When a configuration allowing unsigned Python op scripts is active, a local, low-privileged user can execute malicious scripts as a root-equivalent user.

Business impact

A successful exploit results in total system compromise, allowing an attacker to gain full administrative control over the affected networking hardware. Given the CVSS score of 7.8, this represents a high-severity risk to network integrity: an attacker could manipulate routing traffic, intercept data, or disable critical security controls, leading to significant operational disruption and data exfiltration.

Remediation

Immediate Action: Upgrade to the patched releases provided by Juniper Networks: Junos OS 22.4R3-S7, 23.2R2-S4, 23.4R2-S6, 24.2R1-S2, 24.2R2, 24.4R1-S2, 24.4R2, 25.2R1, or Junos OS Evolved 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S6-EVO, 24.2R2-EVO, 24.4R1-S1-EVO, 24.4R2-EVO, 25.2R1-EVO.

Proactive Monitoring: Audit device configurations to identify the presence of unsigned Python op scripts and review system logs for unauthorized script execution or unexpected privilege elevation events.

Compensating Controls: If immediate patching is not feasible, disable the use of unsigned Python op scripts on all affected devices to eliminate the primary attack vector for this privilege escalation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk of total system compromise posed by this vulnerability necessitates immediate attention. Administrators should verify their current Junos OS versions against the affected list and prioritize the deployment of the vendor-supplied patches to close this critical privilege escalation path.

More Juniper Networks CVEs

Sources