CVE-2026-33776: Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user with low privileges to read sensitive information.
A local user with low privileges can execute the CLI command 'show mgd' with specific arguments which will expose sensitive information.
This issue affects
Junos OS: all versions before 22.4R3-S8, 23.2 versions before 23.2R2-S6, 23.4 versions before 23.4R2-S6, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S1, 25.2 version before 25.2R1-S2, 25.2R2;
Junos OS Evolved: all versions before 23.2R2-S6-EVO, 23.4 version before 23.4R2-S6-EVO, 24.2 version before 24.2R2-S4-EVO, 24.4 versions before 24.4R2-S1-EVO, 25.2 versions before 25.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33776?
CVE-2026-33776 is classified as a Missing Authorization vulnerability in Junos OS that allows local users with low privileges to access sensitive information.
How do I fix CVE-2026-33776?
To fix CVE-2026-33776, update your Junos OS or Junos OS Evolved to the latest version as recommended by Juniper Networks.
Who is affected by CVE-2026-33776?
CVE-2026-33776 affects local users with low privileges on vulnerable versions of Juniper Networks Junos OS and Junos OS Evolved.
What versions are affected by CVE-2026-33776?
The affected versions of CVE-2026-33776 include various releases up to and including 25.2R1-S2 for Junos OS and 25.2R2-EVO for Junos OS Evolved.
What kind of information is exposed by CVE-2026-33776?
CVE-2026-33776 allows low privileged local users to read sensitive information that should be restricted based on user permissions.