CVE-2026-33788: Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs

Published Apr 9, 2026
·
Updated

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device.

A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component.

This issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202:

All versions before 21.2R3-S8-EVO, 21.4-EVO versions before 21.4R3-S7-EVO, 22.2-EVO versions before 22.2R3-S4-EVO, 22.3-EVO versions before 22.3R3-S3-EVO, 22.4-EVO versions before 22.4R3-S2-EVO, 23.2-EVO versions before 23.2R2-EVO.

Affected Software

72 affected components
Juniper Networks Junos OS Evolved (PTX10004/PTX10008/PTX100016 with JNP10K-LC1201 or JNP10K-LC1202)<21.2R3-S8-EVO, >=21.4-EVO<21.4R3-S7-EVO, >=22.2-EVO<22.2R3-S4-EVO, >=22.3-EVO<22.3R3-S3-EVO, >=22.4-EVO<22.4R3-S2-EVO, >=23.2-EVO<23.2R2-EVO
All of the following
Any of the following
Juniper Junos OS Evolved<21.2
Juniper Junos OS Evolved=21.2
Juniper Junos OS Evolved=21.2-r1
Juniper Junos OS Evolved=21.2-r1-s1
Juniper Junos OS Evolved=21.2-r1-s2
Juniper Junos OS Evolved=21.2-r2
Juniper Junos OS Evolved=21.2-r2-s1
Juniper Junos OS Evolved=21.2-r2-s2
Juniper Junos OS Evolved=21.2-r3
Juniper Junos OS Evolved=21.2-r3-s1
Juniper Junos OS Evolved=21.2-r3-s2
Juniper Junos OS Evolved=21.2-r3-s3
Juniper Junos OS Evolved=21.2-r3-s4
Juniper Junos OS Evolved=21.2-r3-s5
Juniper Junos OS Evolved=21.2-r3-s6
Juniper Junos OS Evolved=21.2-r3-s7
Juniper Junos OS Evolved=21.4
Juniper Junos OS Evolved=21.4-r1
Juniper Junos OS Evolved=21.4-r1-s1
Juniper Junos OS Evolved=21.4-r1-s2
Juniper Junos OS Evolved=21.4-r2
Juniper Junos OS Evolved=21.4-r2-s1
Juniper Junos OS Evolved=21.4-r2-s2
Juniper Junos OS Evolved=21.4-r3
Juniper Junos OS Evolved=21.4-r3-s1
Juniper Junos OS Evolved=21.4-r3-s10
Juniper Junos OS Evolved=21.4-r3-s11
Juniper Junos OS Evolved=21.4-r3-s2
Juniper Junos OS Evolved=21.4-r3-s3
Juniper Junos OS Evolved=21.4-r3-s4
Juniper Junos OS Evolved=21.4-r3-s5
Juniper Junos OS Evolved=21.4-r3-s6
Juniper Junos OS Evolved=22.2
Juniper Junos OS Evolved=22.2-r1
Juniper Junos OS Evolved=22.2-r1-s1
Juniper Junos OS Evolved=22.2-r1-s2
Juniper Junos OS Evolved=22.2-r2
Juniper Junos OS Evolved=22.2-r2-s1
Juniper Junos OS Evolved=22.2-r2-s2
Juniper Junos OS Evolved=22.2-r3
Juniper Junos OS Evolved=22.2-r3-s1
Juniper Junos OS Evolved=22.2-r3-s2
Juniper Junos OS Evolved=22.2-r3-s3
Juniper Junos OS Evolved=22.3
Juniper Junos OS Evolved=22.3-r1
Juniper Junos OS Evolved=22.3-r1-s1
Juniper Junos OS Evolved=22.3-r1-s2
Juniper Junos OS Evolved=22.3-r2
Juniper Junos OS Evolved=22.3-r2-s1
Juniper Junos OS Evolved=22.3-r2-s2
Juniper Junos OS Evolved=22.3-r3
Juniper Junos OS Evolved=22.3-r3-s1
Juniper Junos OS Evolved=22.3-r3-s2
Juniper Junos OS Evolved=22.4
Juniper Junos OS Evolved=22.4-r1
Juniper Junos OS Evolved=22.4-r1-s1
Juniper Junos OS Evolved=22.4-r1-s2
Juniper Junos OS Evolved=22.4-r2
Juniper Junos OS Evolved=22.4-r2-s1
Juniper Junos OS Evolved=22.4-r2-s2
Juniper Junos OS Evolved=22.4-r3
Juniper Junos OS Evolved=22.4-r3-s1
Juniper Junos OS Evolved=23.2
Juniper Junos OS Evolved=23.2-r1
Juniper Junos OS Evolved=23.2-r1-s1
Juniper Junos OS Evolved=23.2-r1-s2
Any of the following
Juniper JNP10K-LC1201
Juniper JNP10K-LC1202
Juniper PTX100016
Juniper PTX10004
Juniper PTX10008

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 21.2R3-S8-EVO
  2. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 21.4R3-S7-EVO
  3. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.2R3-S4-EVO
  4. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.3R3-S3-EVO
  5. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 22.4R3-S2-EVO
  6. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 23.2R2-EVO
  7. Upgrade

    Upgrade Juniper Networks Junos OS Evolved to a version that resolves this vulnerability.

    Fixed in 23.4R1-EVO

Event History

Apr 9, 2026
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33788?

CVE-2026-33788 is a critical vulnerability that allows local, authenticated attackers to gain privileged access, potentially compromising the system's security.

2

How do I fix CVE-2026-33788?

To fix CVE-2026-33788, update Junos OS Evolved to the patched versions specified by Juniper Networks, ensuring to follow their official guidelines.

3

Who is affected by CVE-2026-33788?

CVE-2026-33788 affects users of Juniper Networks Junos OS Evolved on PTX Series devices, specifically those running vulnerable versions listed by the vendor.

4

What kind of access can be gained through CVE-2026-33788?

An attacker exploiting CVE-2026-33788 can gain privileged access to Flexible PIC Concentrators (FPCs) from a local system.

5

Is authentication required to exploit CVE-2026-33788?

Yes, CVE-2026-33788 requires the attacker to be a local, authenticated user with low privileges to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203