{"id":"CVE-2026-33788","title":"A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …","summary":"A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"juniper","product":"junos","affected":["junos < 21.2","junos = 21.2","junos = 21.4","junos = 22.2","junos = 22.3","junos = 22.4","junos = 23.2"],"patched":["junos 21.2"],"published":"2026-04-09","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33788","references":[{"url":"https://kb.juniper.net/JSA107806","label":"sirt@juniper.net"}],"tags":["nvd"],"epss":0.00114,"epssPercentile":0.01724,"ingestedAt":"2026-07-08T03:46:38.639Z","slug":"CVE-2026-33788","body":"## Overview\n\nA Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Networks Junos OS Evolved on PTX Series allows a local, authenticated attacker with low privileges to gain direct access to FPCs installed in the device.\n\nA local user with low privileges can gain direct access to the installed FPCs as a high privileged user, which can potentially lead to a full compromise of the affected component.\n\nThis issue affects Junos OS Evolved on PTX10004, PTX10008, PTX100016, with JNP10K-LC1201 or JNP10K-LC1202:\n\n\n\n\n  *  All versions before 21.2R3-S8-EVO,\n  *  21.4-EVO versions before 21.4R3-S7-EVO,\n  *  22.2-EVO versions before 22.2R3-S4-EVO,\n  *  22.3-EVO versions before 22.3R3-S3-EVO,\n  *  22.4-EVO versions before 22.4R3-S2-EVO,\n  *  23.2-EVO versions before 23.2R2-EVO.\n\n## Affected\n\n- `junos < 21.2`\n- `junos = 21.2`\n- `junos = 21.4`\n- `junos = 22.2`\n- `junos = 22.3`\n- `junos = 22.4`\n- `junos = 23.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `junos 21.2`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}