#VU125557 Missing Authorization in Junos OS - CVE-2026-33785
Published: April 9, 2026
Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a local user to execute specific commands to completely compromise managed devices.
The vulnerability exists due to missing authorization in the CLI when handling 'request csds' CLI operational commands in a JDM/CSDS scenario. A local user can issue 'request csds' commands to completely compromise managed devices.
Only MX Series devices in a JDM/CSDS deployment scenario are affected.