CVE-2026-33788 is a missing authentication vulnerability in Juniper Networks Junos OS Evolved affecting PTX Series routers equipped with specific line card modules (JNP10K-LC1201 or JNP10K-LC1202). The vulnerability allows authenticated local users with low privileges to bypass authentication controls and gain unauthorized access to Flexible PIC Concentrators (FPCs) as a high-privileged user. This affects multiple PTX models and numerous software versions across the 21.2 through 23.2 release lines. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring low-level authentication. The attack has low complexity and requires no user interaction, resulting in high confidentiality, integrity, and availability impacts. Successful exploitation could lead to complete compromise of the affected FPC component and potentially the broader network infrastructure. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, indicating no active exploitation in the wild at this time. Exploit code availability has not been reported, and community attention remains minimal based on the inactive hot list status. However, organizations running the affected Junos OS Evolved versions should implement available patches prioritized by their release timeline to mitigate potential future risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:21.2:-:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:21.2:r1:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s1:*:*:*:*:*:* | ||
21.2CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:21.2:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.