CVE-2026-33802 Details
Description
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers. This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400: * 23.2R2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1.
A missing authorization vulnerability has been identified in the CLI of Juniper Networks Junos OS, specifically on EX Series switches including EX2300, EX4000, EX4100, EX4300-MP (Multigigabit), and EX4400. This vulnerability allows a local, authenticated attacker to cause a denial-of-service (DoS) condition. An attacker can execute a privileged 'request' command that disrupts traffic until the system automatically recovers. The vulnerability affects several versions of Junos OS: 23.2R2 prior to 23.2R2-S6, 23.4 prior to 23.4R2-S8, 24.2 prior to 24.2R2-S4, 24.4 prior to 24.4R2-S3, 25.2 prior to 25.2R2, and 25.4 prior to 25.4R1-S1.
Users can upgrade to Junos OS versions 23.2R2-S6, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1-S1, 25.4R2, 26.2R1, or any subsequent release. To reduce the risk of exploitation, command authorization can be used to limit access to 'request' commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110077 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 23.4 r2-s7 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 25.4 - 25.4 r1 |
CPE
Remediation
| |
| juniper ex2300 | All versions |
CPE
Remediation
| |
| juniper ex4000 | All versions |
CPE
Remediation
| |
| juniper ex4100 | All versions |
CPE
Remediation
| |
| juniper ex4300-mp | All versions |
CPE
Remediation
| |
| juniper ex4400 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |