Junglewise Threat Intelligence

CVE-2026-21904: Juniper Networks Junos Space XSS in list filter field

CVE-2026-21904 · Severity: medium · CVSS 6.1 · Published 2026-04-09

Vendors: Juniper Networks.

Executive brief

Juniper Networks Junos Space, a platform used to manage network devices, contains a security vulnerability in its list filter field. An attacker can use this flaw to execute malicious commands with the permissions of any user who views the affected page, including administrators. This could lead to unauthorized configuration changes or access to sensitive network management data.

Technical details

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the list filter field of Juniper Networks Junos Space. By injecting malicious script tags into this field, an attacker can execute arbitrary JavaScript in the context of another user's browser session when they visit the affected page. This is a stored XSS attack that requires user interaction (viewing the filtered list) but no prior authentication to inject the payload. Successful exploitation allows the attacker to perform actions with the victim's privileges, potentially gaining full administrative control over the Junos Space instance. The issue is resolved in Junos Space 24.1R5 Patch V3 and all subsequent releases.

Affected products

  • Juniper Networks Junos Space All versions before 24.1R5 Patch V3

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory
  • 2026-04-09: patched: Fixed in 24.1R5 Patch V3

References