PT-2026-31743 · Juniper Networks · Junos Space
Published
2026-04-09
·
Updated
2026-04-10
·
CVE-2026-21904
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Juniper Networks Junos Space versions prior to 24.1R5 Patch V3
Description
A flaw exists in Juniper Networks Junos Space that allows an attacker to inject script tags into the list filter field. When another user visits the affected page, the attacker can execute commands with the target user's permissions, potentially including administrator privileges.
Recommendations
Update to Junos Space 24.1R5 Patch V3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Space