# CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box Anomaly Detection Framework (CVSS 9.8)

> Critical unauthenticated remote code execution vulnerability in Juniper Networks PTX Series routers running Junos OS Evolved. The On-Box Anomaly Detection Framework exposes a Python REST API on port 8160/TCP bound to all interfaces without authentication, allowing any network-based attacker to execute arbitrary commands as root via crafted API requests. CVSS 9.8 with no user interaction required.

- **Published:** 2026-03-22T12:00:00Z
- **Last reviewed:** 2026-07-19T10:08:42.983Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0269
- **ID:** TL-2026-0269
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-21902

## Description

CVE-2026-21902 is a critical pre-authentication remote code execution vulnerability affecting Juniper Networks PTX Series routers running Junos OS Evolved version 25.4R1-EVO. The flaw resides in the On-Box Anomaly Detection Framework, an internal security monitoring service that was inadvertently exposed to external network access due to incorrect default permissions (CWE-276/CWE-732).

The vulnerability stems from a Python-based REST API server (api_server.py) that binds to 0.0.0.0:8160/TCP instead of the localhost interface. This service is part of the On-Box Anomaly Detection Framework and was designed to be reachable only by other internal processes over the internal routing instance. However, the incorrect permission assignment causes the service to listen on all network interfaces, making it accessible to any unauthenticated remote attacker.

The exploitation chain leverages four REST API endpoints that require no authentication:

1. POST /config/command/<name> — Creates a Command definition with type RE-SHELL containing arbitrary shell syntax
2. POST /config/dag/<name> — Defines a DAG (Directed Acyclic Graph) workflow referencing the malicious command
3. POST /config/dag-instance/<name> — Creates a scheduled execution instance with immediate timing
4. POST /config/commit — Validates and persists the configuration, triggering execution

When the schedule_enforcer.py process (running as root) detects the scheduled DAG instance, it retrieves the command definition and passes the attacker-controlled syntax field directly to subprocess.run(command, shell=True), achieving arbitrary command execution with root privileges. The vulnerable code path flows through execute_dag_instance() -> execute_dag() -> run_bfs_on_dag_actions() -> execute_command(), with no input sanitization at any stage.

The service is enabled by default on affected versions without requiring any specific configuration, meaning all PTX Series routers running vulnerable Junos OS Evolved versions are exposed out of the box. Successful exploitation grants complete device control including configuration manipulation (routing tables, BGP sessions, ACLs), traffic interception or redirection, credential and cryptographic key exfiltration, and service disruption via control-plane interference.

Juniper Networks released this as an out-of-cycle emergency security bulletin (JSA107128) on February 25, 2026, indicating the severity and urgency. The watchTowr Labs team published a detailed technical analysis and proof-of-concept on March 3, 2026, demonstrating the full exploitation chain. Multiple government agencies including the Cyber Security Agency of Singapore issued alerts. No confirmed active exploitation in the wild has been reported, though the trivial exploitation complexity and public PoC availability make exploitation highly likely.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1040 Network Sniffing
- T1071 Application Layer Protocol
- T1489 Service Stop
- T1565 Data Manipulation
- T1498 Network Denial of Service
- T1595.001 Active Scanning: Scanning IP Blocks
- T1595.002 Active Scanning: Vulnerability Scanning
- T1211 Exploitation for Stealth
- T1505 Server Software Component
- T1495 Firmware Corruption
- T1210 Exploitation of Remote Services

## Sources

- [Juniper Out-of-Cycle Security Bulletin JSA107128](https://supportportal.juniper.net/JSA107128)
- [NVD - CVE-2026-21902](https://cvefeed.io/vuln/detail/CVE-2026-21902)
- [watchTowr Labs: Junos OS Evolved CVE-2026-21902 Pre-Auth RCE Analysis](https://labs.watchtowr.com/sometimes-you-can-just-feel-the-security-in-the-design-junos-os-evolved-cve-2026-21902-rce/)
- [watchTowr Labs PoC - CVE-2026-21902](https://github.com/watchtowrlabs/watchTowr-vs-JunosEvolved-CVE-2026-21902)
- [Purple Ops CVE-2026-21902 Technical Analysis](https://www.purple-ops.io/resources-hottest-cves/cve-2026-21902-junos-rce/)
- [CVE-2026-21902: Juniper PTX Routers One Packet to Root](https://dev.to/deepseax/cve-2026-21902-juniper-ptx-routers-one-packet-to-root-cvss-98-46na)
- [Critical Juniper PTX Junos OS Evolved Flaw Enables Unauthenticated Root Takeover](https://www.threatintelreport.com/2026/02/26/vulnerabilities_exploits/critical-juniper-ptx-junos-os-evolved-flaw-enables-unauthenticated-root-takeover-cve-2026-21902/)
- [Cyber Security Agency of Singapore Alert AL-2026-020](https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-020/)
- [Critical Flaw in Juniper PTX Routers: Unauthenticated Root Access Discovered](https://securityonline.info/critical-flaw-in-juniper-ptx-routers-unauthenticated-root-access-discovered/)
- [Juniper Issues Emergency Patch for Critical PTX Router RCE](https://securityaffairs.com/188609/security/juniper-issues-emergency-patch-for-critical-ptx-router-rce.html)
- [runZero: Juniper Junos OS Evolved CVE-2026-21902 Detection](https://www.runzero.com/blog/junos-os-evo/)
- [Cyble Weekly Vulnerabilities Report - March 19, 2026](https://cyble.com/blog/cyble-weekly-vulnerabilities-report-mar-19/)
- [UpGuard: Critical Juniper Networks RCE CVE-2026-21902](https://www.upguard.com/news/juniper-networks-data-breach-2026-03-02)
- [Rescana: Critical CVE-2026-21902 Vulnerability Analysis](https://www.rescana.com/post/critical-cve-2026-21902-vulnerability-in-juniper-networks-ptx-series-routers-running-junos-os-evolve)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0269
