Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33788

30
FAUCET Score

CVE-2026-33788 is a missing authentication vulnerability in Juniper Networks Junos OS Evolved affecting PTX Series routers equipped with specific line card modules (JNP10K-LC1201 or JNP10K-LC1202). The vulnerability allows authenticated local users with low privileges to bypass authentication controls and gain unauthorized access to Flexible PIC Concentrators (FPCs) as a high-privileged user. This affects multiple PTX models and numerous software versions across the 21.2 through 23.2 release lines. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring low-level authentication. The attack has low complexity and requires no user interaction, resulting in high confidentiality, integrity, and availability impacts. Successful exploitation could lead to complete compromise of the affected FPC component and potentially the broader network infrastructure. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, indicating no active exploitation in the wild at this time. Exploit code availability has not been reported, and community attention remains minimal based on the inactive hot list status. However, organizations running the affected Junos OS Evolved versions should implement available patches prioritized by their release timeline to mitigate potential future risks.

Impacted Technologies

VendorProductVersion(s)CPE
< 21.2CPE matchmatch criteria
cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:*
21.2CPE matchmatch criteria
cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:*
21.2CPE matchmatch criteria
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1:*:*:*:*:*:*
21.2CPE matchmatch criteria
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s1:*:*:*:*:*:*
21.2CPE matchmatch criteria
cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 8th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

junipervendor investigatingvia vendor_rss
View patch

Vendor Advisories (1)

juniperjuniper:ka0Dp000000vCWbIAM

2026-04 Security Bulletin: Junos OS Evolved: Local, authenticated attackers can gain access to FPCs (CVE-2026-33788)

Apr 8, 2026

References

kb.juniper.net / JSA107806
Vendor Advisory