PT-2026-31743 · Juniper Networks · Junos Space

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-21904

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos Space versions prior to 24.1R5 Patch V3
Description A flaw exists in Juniper Networks Junos Space that allows an attacker to inject script tags into the list filter field. When another user visits the affected page, the attacker can execute commands with the target user's permissions, potentially including administrator privileges.
Recommendations Update to Junos Space 24.1R5 Patch V3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21904

Affected Products

Junos Space