Junglewise Threat Intelligence

CVE-2026-33788: Juniper Junos OS Evolved auth bypass in Flexible PIC Concentrators

CVE-2026-33788 · Severity: high · CVSS 7.8 · Published 2026-04-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A security vulnerability in Juniper Networks Junos OS Evolved allows a user with low-level access to gain full control over specific hardware components (Flexible PIC Concentrators) on PTX Series routers. This could allow an internal attacker to bypass security restrictions and compromise the integrity or availability of the networking equipment. Organizations using PTX10004, PTX10008, or PTX100016 series devices should apply the provided software updates to prevent unauthorized administrative access.

Technical details

A Missing Authentication for Critical Function (CWE-306) vulnerability exists in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series devices. The flaw allows a local, authenticated attacker with low privileges to bypass authentication mechanisms and gain direct access to the FPCs as a high-privileged user. This access can lead to a full compromise of the affected hardware component. The issue specifically impacts PTX10004, PTX10008, and PTX100016 models equipped with JNP10K-LC1201 or JNP10K-LC1202 line cards. Fixed versions have been released across multiple Junos OS Evolved release trains.

Affected products

  • Juniper Networks Junos OS Evolved All versions before 21.2R3-S8-EVO; 21.4-EVO before 21.4R3-S7-EVO; 22.2-EVO before 22.2R3-S4-EVO; 22.3-EVO before 22.3R3-S3-EVO; 22.4-EVO before 22.4R3-S2-EVO; 23.2-EVO before 23.2R2-EVO

Timeline

  • 2026-04-09: disclosed: Initial advisory publication
  • 2026-04-09: advisory: Juniper JSA107806 published

References

Related threats