Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33793

28
FAUCET Score

CVE-2026-33793 is a privilege escalation vulnerability affecting Juniper Networks Junos OS and Junos OS Evolved. The flaw exists in the User Interface component and allows local, low-privileged users to execute unsigned Python op scripts as root-equivalent users when such scripts are configured on the device, thereby gaining full system compromise. The vulnerability impacts all major versions of both platforms, with fixes available in specific patched releases across versions 22.4 through 24.4. The vulnerability carries a HIGH severity rating with a CVSS score of 7.8. Attack exploitation requires local access and low privileges, with no user interaction necessary and low attack complexity, making it relatively straightforward to exploit once an attacker has obtained initial system access. The impact is critical, as successful exploitation grants attackers root-level privileges with complete confidentiality, integrity, and availability compromise possible. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains on inactive status regarding public exploit availability. However, the FAUCET risk score of 49.0/100 indicates moderate community attention and concern relative to other disclosed vulnerabilities, warranting prompt patching of affected systems.

Impacted Technologies

VendorProductVersion(s)CPE
< 22.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*
22.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*
22.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*
22.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*
22.4CPE matchmatch criteria
cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 24th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

junipervendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

juniperjuniper:ka0Dp000000vENvIAMLOW

2026-04 Security Bulletin: Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system (CVE-2026-33793)

Apr 16, 2026
juniperjuniper:ka0Dp000000vDwBIAULOW

2026-04 Security Bulletin: Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system (CVE-2026-33793)

Apr 9, 2026

References

supportportal.juniper.net / JSA103142
MitigationVendor Advisory