CVE-2026-21902 Details
Description
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.
A vulnerability allowing unauthenticated, network-based code execution as root has been identified in the On-Box Anomaly Detection framework of Juniper Networks Junos OS Evolved, specifically on PTX Series routers. This vulnerability arises from incorrect permission assignments that expose the anomaly detection service on externally accessible ports, contrary to its intended design of being available only to internal processes via the internal routing instance. As a result, a remote attacker could potentially gain complete control over the affected device. This issue affects Junos OS Evolved versions 25.4 prior to 25.4R1-S1-EVO and 25.4R2-EVO, and is present by default without requiring any specific configuration.
Users can upgrade to Junos OS Evolved versions 25.4R1-S1-EVO, 25.4R2-EVO, 26.2R1-EVO, or any subsequent release. Alternatively, the On-Box Anomaly Detection service can be disabled using the command 'request pfe anomalies disable'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/watchtowrlabs/watchTowr-vs-JunosEvolved-CVE-2026-21902/blob/main/watchTowr-vs-JunosEvolved-CVE-2026-21902.py | CISA-ADP | Product |
| https://kb.juniper.net/JSA107128 | [email protected] | MitigationVendor Advisory |
| https://supportportal.juniper.net/JSA107128 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos os evolved | 25.4 r1 |
CPE
Remediation
| |
| juniper ptx10001-36mr | All versions |
CPE
Remediation
| |
| juniper ptx10002-36qdd | All versions |
CPE
Remediation
| |
| juniper ptx10003 | All versions |
CPE
Remediation
| |
| juniper ptx10004 | All versions |
CPE
Remediation
| |
| juniper ptx10008 | All versions |
CPE
Remediation
| |
| juniper ptx10016 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | [email protected] |