Incorrect Permission Assignment Vulnerability in Juniper Networks Junos OS Evolved on PTX Series
CVE-2026-21902

9.3CRITICAL

Key Information:

Vendor
CVE Published:
25 February 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-21902?

An Incorrect Permission Assignment vulnerability exists in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved, specifically impacting the PTX Series. This vulnerability permits unauthenticated network-based attackers to execute code with root privileges. The framework, which should only be accessible by internal processes, is erroneously exposed via an external port by default, thereby allowing remote attackers to gain complete control over affected devices without any specialized configuration needed. Users are advised to apply the necessary updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Junos OS Evolved PTX Series 25.4 < 25.4R1-S1-EVO, 25.4R2-EVO

Junos OS Evolved PTX Series 0 < 25.4R1-EVO

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.