A Missing Authorization vulnerability (CVE-2026-33785) affects Juniper Networks Junos OS on MX Series devices, allowing authenticated local users with low privileges to execute restricted CLI commands designated for high-privilege administrators and Juniper Device Manager operations. The vulnerability impacts Junos OS 24.4 releases before 24.4R2-S3 and 25.2 releases before 25.2R2, with no impact on releases prior to version 24.4. The vulnerability carries a CVSS score of 8.8 (HIGH) with a local attack vector and low complexity requirement. Once authenticated to the device, a low-privilege user can execute 'request csds' commands without additional authorization checks, achieving high impact across confidentiality, integrity, and availability of managed devices. The attack requires local access and low privileges but results in complete compromise of the managed infrastructure. Exploitation status remains minimal at present, with no public exploit code available and no indication of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) list and remains inactive on industry hot lists, suggesting limited community attention and exploitation attempts to date. Organizations should still prioritize patching given the high severity rating and the ease of exploitation for any authenticated local user.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 24.4, < 24.4R2-S3CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 25.2, < 25.2R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
2026-04 Security Bulletin: Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario (CVE-2026-33785)
Apr 9, 20262026-04 Security Bulletin: Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario (CVE-2026-33785)
Apr 8, 2026