📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 7h Global insider Education HIGH 1d Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 2d Global data_breach Government HIGH 2d Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 7h Global insider Education HIGH 1d Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 2d Global data_breach Government HIGH 2d Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 7h Global insider Education HIGH 1d Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 2d Global data_breach Government HIGH 2d
Vulnerabilities

CVE-2026-33793

High
CWE-250 — Weakness Type
Published: Apr 9, 2026  ·  Modified: Apr 16, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.

When a configuration that allows unsigned Python op scripts is present on the device, a non-root user is able to execute malicious op scripts as a root-equivalent user, leading to privilege escalation. 

This issue affects Junos OS: 

* All versions before 22.4R3-S7, 
* from 23.2 before 23.2R2-S4, 
* from 23.4 before 23.4R2-S6,
* from 24.2 before 24.2R1-S2, 24.2R2, 
* from 24.4 before 24.4R1-S2, 24.4R2; 




Junos OS Evolved: 



* All versions before 22.4R3-S7-EVO, 
* from 23.2 before 23.2R2-S4-EVO, 
* from 23.4 before 23.4R2-S6-EVO,
* from 24.2 before 24.2R2-EVO, 
* from 24.4 before 24.4R1-S1-EVO, 24.4R2-EVO.

🤖 AI Executive Summary

A privilege escalation vulnerability in Juniper Networks Junos OS allows local, low-privileged users to execute arbitrary Python op scripts with root privileges when unsigned script execution is enabled. This critical flaw affects multiple Junos OS versions and could enable complete system compromise. Immediate configuration review and version upgrades are essential for Saudi organizations operating Juniper network infrastructure.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 28, 2026 13:00
🇸🇦 Saudi Arabia Impact Assessment
High impact on Saudi critical infrastructure sectors: (1) Banking & Financial Services (SAMA-regulated institutions) — Juniper devices commonly used in core network infrastructure and payment systems; (2) Government & Defense (NCA oversight) — widespread deployment in government networks and secure communications; (3) Telecommunications (STC, Mobily, Zain) — backbone network equipment; (4) Energy Sector (Saudi Aramco, SEC) — operational technology networks; (5) Healthcare — hospital network infrastructure. Local access requirement limits exposure but insider threats and compromised service accounts pose significant risk. Privilege escalation to root enables lateral movement, data exfiltration, and persistent backdoors.
🏢 Affected Saudi Sectors
Banking & Financial Services Government & Defense Telecommunications Energy & Utilities Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all Juniper Junos devices for unsigned Python op script configurations — disable if not operationally required
2. Restrict local user access to devices via SSH/console to authorized personnel only
3. Implement strong authentication (SSH keys, MFA) for all local accounts
4. Review user privilege levels and apply principle of least privilege

PATCHING GUIDANCE:
1. Upgrade to patched versions: 22.4R3-S7+, 23.2R2-S4+, 23.4R2-S6+, 24.2R1-S2/24.2R2+, 24.4R1-S2/24.4R2+ (or EVO equivalents)
2. Prioritize devices in banking, government, and telecom sectors
3. Test patches in lab environment before production deployment
4. Schedule maintenance windows with minimal network impact

COMPENSATING CONTROLS (if patching delayed):
1. Disable unsigned Python op script execution via configuration: set system scripts op file <filename> signed
2. Implement network segmentation to limit local access to management interfaces
3. Deploy host-based intrusion detection on management networks
4. Monitor for suspicious op script execution attempts

DETECTION RULES:
1. Alert on any op script execution by non-root users
2. Monitor for Python script files in /var/db/scripts/op/ directory
3. Track privilege escalation attempts in system logs
4. Flag unsigned script execution attempts
5. Monitor for unexpected root process spawning from UI/op script contexts
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع أجهزة Juniper Junos للتحقق من إعدادات سكريبتات Python غير الموقعة — تعطيلها إن لم تكن مطلوبة تشغيلياً
2. تقييد الوصول المحلي للأجهزة عبر SSH/console للموظفين المصرح لهم فقط
3. تطبيق المصادقة القوية (مفاتيح SSH، المصادقة متعددة العوامل) لجميع الحسابات المحلية
4. مراجعة مستويات امتيازات المستخدمين وتطبيق مبدأ الحد الأدنى من الامتيازات

إرشادات التصحيح:
1. الترقية إلى الإصدارات المصححة: 22.4R3-S7+، 23.2R2-S4+، 23.4R2-S6+، 24.2R1-S2/24.2R2+، 24.4R1-S2/24.4R2+ (أو ما يعادلها EVO)
2. إعطاء الأولوية للأجهزة في قطاعات البنوك والحكومة والاتصالات
3. اختبار التصحيحات في بيئة المختبر قبل النشر الإنتاجي
4. جدولة نوافذ الصيانة بأقل تأثير على الشبكة

الضوابط البديلة (إذا تأخر التصحيح):
1. تعطيل تنفيذ سكريبتات Python غير الموقعة عبر الإعدادات: set system scripts op file <filename> signed
2. تطبيق تقسيم الشبكة لتقييد الوصول المحلي لواجهات الإدارة
3. نشر كشف الاختراق على مستوى المضيف على شبكات الإدارة
4. مراقبة محاولات تنفيذ سكريبتات op المريبة

قواعد الكشف:
1. تنبيه عند تنفيذ أي سكريبت op من قبل مستخدمين غير جذر
2. مراقبة ملفات سكريبتات Python في دليل /var/db/scripts/op/
3. تتبع محاولات تصعيد الامتيازات في سجلات النظام
4. وضع علامة على محاولات تنفيذ السكريبتات غير الموقعة
5. مراقبة توليد عمليات جذر غير متوقعة من سياقات UI/op script
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.9.2.1 — User access management and privilege control ECC 2024 A.9.4.3 — Password management and authentication ECC 2024 A.12.4.1 — Event logging and monitoring ECC 2024 A.14.2.1 — System change management and configuration control
🔵 SAMA CSF
SAMA CSF ID.AM-2 — Hardware and software asset management SAMA CSF PR.AC-1 — Access control policy and procedures SAMA CSF PR.AC-4 — Access rights and privilege management SAMA CSF DE.CM-1 — System monitoring and anomaly detection
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 — Access control ISO 27001:2022 A.8.2 — Privileged access rights ISO 27001:2022 A.8.3 — Information access restriction ISO 27001:2022 A.12.4.1 — Event logging
🟣 PCI DSS v4.0.1
PCI DSS 2.1 — Default security parameters PCI DSS 7.1 — Limit access to system components by business need PCI DSS 8.1 — Assign unique ID to each person with computer access PCI DSS 10.2 — Implement automated audit trails
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-250
EPSS0.01%
Exploit No
Patch ✗ No
Published 2026-04-09
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-250
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.