🔐 CVE Alert

CVE-2026-33788

HIGH 7.8

Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
3th

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device. A local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component. This issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202: * All versions before 21.2R3-S8-EVO, * 21.4-EVO versions before 21.4R3-S7-EVO, * 22.2-EVO versions before 22.2R3-S4-EVO, * 22.3-EVO versions before 22.3R3-S3-EVO, * 22.4-EVO versions before 22.4R3-S2-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CWE CWE-306
Vendor juniper networks
Product junos os evolved
Published Apr 9, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for juniper networks junos os evolved

Be the first to know when new high vulnerabilities affecting juniper networks junos os evolved are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Juniper Networks / Junos OS Evolved
0 < 21.2R3-S8-EVO 21.4-EVO < 21.4R3-S7-EVO 22.2-EVO < 22.2R3-S4-EVO 22.3-EVO < 22.3R3-S3-EVO 22.4-EVO < 22.4R3-S2-EVO 23.2-EVO < 23.2R2-EVO

References

NVD ↗ CVE.org ↗ EPSS Data ↗
kb.juniper.net: https://kb.juniper.net/JSA107806