CVE-2026-33793: Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.
When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation.
This issue affects Junos OS:
All versions before 22.4R3-S7, from 23.2 before 23.2R2-S4, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R1-S2, 24.2R2, from 24.4 before 24.4R1-S2, 24.4R2;
Junos OS Evolved:
All versions before 22.4R3-S7-EVO, from 23.2 before 23.2R2-S4-EVO, from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-EVO, from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33793?
CVE-2026-33793 is classified as a low severity vulnerability in Junos OS and Junos OS Evolved.
How do I fix CVE-2026-33793?
To fix CVE-2026-33793, upgrade to the appropriate patched version of Junos OS or Junos OS Evolved as specified in Juniper's security advisories.
What versions are affected by CVE-2026-33793?
CVE-2026-33793 affects Junos OS versions up to 22.4R3-S7 and specific versions in the 23.x and 24.x series.
Who is vulnerable to CVE-2026-33793?
Local, low-privileged users of affected versions of Junos OS and Junos OS Evolved are vulnerable to CVE-2026-33793.
What impact does CVE-2026-33793 have?
The impact of CVE-2026-33793 allows a local low-privileged user to execute operations with unnecessary privileges on the system.