Executive brief
Juniper Networks Junos Space, a platform used to manage network devices, contains a security vulnerability in its list filter field. An attacker can use this flaw to execute malicious commands with the permissions of any user who views the affected page, including administrators. This could lead to unauthorized configuration changes or access to sensitive network management data.
Technical details
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the list filter field of Juniper Networks Junos Space. By injecting malicious script tags into this field, an attacker can execute arbitrary JavaScript in the context of another user's browser session when they visit the affected page. This is a stored XSS attack that requires user interaction (viewing the filtered list) but no prior authentication to inject the payload. Successful exploitation allows the attacker to perform actions with the victim's privileges, potentially gaining full administrative control over the Junos Space instance. The issue is resolved in Junos Space 24.1R5 Patch V3 and all subsequent releases.
Affected products
- Juniper Networks Junos Space All versions before 24.1R5 Patch V3
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory
- 2026-04-09: patched: Fixed in 24.1R5 Patch V3