CVE-2026-21902 describes a critical Incorrect Permission Assignment vulnerability (CWE-732) in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series devices, enabling unauthenticated, network-based remote code execution as root. This impacts specific 25.4 versions of Junos OS Evolved on PTX Series. Rated 9.8 Critical (CVSSv3.1), this vulnerability has a low attack complexity and requires no authentication or user interaction, allowing a remote attacker to gain complete control over affected devices. Although not currently in CISA's KEV catalog, exploit code is reported to exist, and the vulnerability is garnering significant community discussion and media attention due to its pre-authentication remote code execution capabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
25.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos_os_evolved:25.4:r1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
2026-02 Out-of-Cycle Security Bulletin: Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root (CVE-2026-21902)
Mar 3, 20262026-02 Out-of-Cycle Security Bulletin: Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root (CVE-2026-21902)
Feb 25, 2026