CVE-2026-33785Disclosure(juniper / junos)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch juniper junos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations as they will impact all aspects of the devices managed via the respective MX. This issue affects Junos OS on MX Series: * 24.4 releases before 24.4R2-S3,  * 25.2 releases before 25.2R2. This issue does not affect Junos OS releases before 24.4.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • junos
  • mx10004
  • mx10008
  • mx2008

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
junosmx10004mx10008mx2008mx2010mx2020mx204mx240mx301mx304

3 versions affected across 12 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-14: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-1004-14
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Patch1
2026-04-101
Disclosure1
2026-04-141
General1
Full discourse4 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Juniper Networks ❗ CVE-2026-33793 ❗ CVE-2026-33788 ❗ CVE-2026-33785 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-juniper-networks-2/ https://t.co/Z6HVR8JysF

    Post summary

    The post lists three Juniper Networks CVEs but provides no technical, exploit, or mitigation details.

    00010226
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33785 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific … https://www.cve.org/CVERecord?id=CVE-2026-33785

    Post summary

    The post announces a missing‑authorization vulnerability in Juniper Networks Junos OS that lets low‑privileged local users run commands, but it offers no proof‑of‑concept, exploit tools, or active exploitation evidence.

    00001149
    57.0K followersView on X
  • dbugs@ptdbugs
    Disclosure

    Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario CVE: CVE-2026-33785 PT ID: PT-2026-31804 Vendor: Juniper networks Product: Junos OS CVSS: 8.8 Credits: n/a Description: A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations as they will impact all aspects of the devices managed via the respective MX. This issue affects Junos OS on MX Series: * 24.4 releases before 24.4R2-S3,  * 25.2 releases before 25.2R2. This issue does not affect Junos OS releases before 24.4. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33785 • https://kb.juniper.net/JSA107872 #dbugs_vuln

    Post summary

    Juniper’s Junos OS on MX Series suffers from a missing authorization flaw (CVE-2026-33785) that allows low‑privileged local users to run privileged commands, potentially leading to full device compromise.

    00000182
    788 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33785: HIGH] Critical Missing Authorization vulnerability in Juniper Networks Junos OS on MX Series allows low-privileged users to compromise devices. Update to versions 24.4R2-S3 or 25.2R2 to patch.#cve,CVE-2026-33785,#cybersecurity https://cvefind.com/CVE-2026-33785

    Post summary

    The post highlights a critical missing authorization flaw in Juniper Junos OS and directs users to specific firmware updates to mitigate the vulnerability.

    0000061
    619 followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos24.4--
OSjuniperjunos25.2--
OSjuniperjunos25.2--
OSjuniperjunos25.2--
OSjuniperjunos25.2--
HWjunipermx10004---
HWjunipermx10008---
HWjunipermx2008---
HWjunipermx2010---
HWjunipermx2020---
HWjunipermx204---
HWjunipermx240---
HWjunipermx301---
HWjunipermx304---
HWjunipermx480---
HWjunipermx960---

Explore more