CVE-2026-33793 is a privilege escalation vulnerability affecting Juniper Networks Junos OS and Junos OS Evolved. The flaw exists in the User Interface component and allows local, low-privileged users to execute unsigned Python op scripts as root-equivalent users when such scripts are configured on the device, thereby gaining full system compromise. The vulnerability impacts all major versions of both platforms, with fixes available in specific patched releases across versions 22.4 through 24.4. The vulnerability carries a HIGH severity rating with a CVSS score of 7.8. Attack exploitation requires local access and low privileges, with no user interaction necessary and low attack complexity, making it relatively straightforward to exploit once an attacker has obtained initial system access. The impact is critical, as successful exploitation grants attackers root-level privileges with complete confidentiality, integrity, and availability compromise possible. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains on inactive status regarding public exploit availability. However, the FAUCET risk score of 49.0/100 indicates moderate community attention and concern relative to other disclosed vulnerabilities, warranting prompt patching of affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
2026-04 Security Bulletin: Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system (CVE-2026-33793)
Apr 16, 20262026-04 Security Bulletin: Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system (CVE-2026-33793)
Apr 9, 2026