Incorrect Permission Assignment Vulnerability in Juniper Networks Junos OS Evolved on PTX Series
CVE-2026-21902
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 25 February 2026
Badges
What is CVE-2026-21902?
An Incorrect Permission Assignment vulnerability exists in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved, specifically impacting the PTX Series. This vulnerability permits unauthenticated network-based attackers to execute code with root privileges. The framework, which should only be accessible by internal processes, is erroneously exposed via an external port by default, thereby allowing remote attackers to gain complete control over affected devices without any specialized configuration needed. Users are advised to apply the necessary updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Junos OS Evolved PTX Series 25.4 < 25.4R1-S1-EVO, 25.4R2-EVO
Junos OS Evolved PTX Series 0 < 25.4R1-EVO
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved