CVE-2026-21904: Junos Space: ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site script injection
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the
list filter field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.
This issue affects all versions of Junos Space before 24.1R5 Patch V3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos Spaceto a version that resolves this vulnerability.Fixed in 24.1R5 Patch V3 - Configuration
Ensure the ilpFilter field on nLegacy.jsp properly neutralizes user-supplied content during web page generation to prevent reflected cross-site scripting.
Junos Space (nLegacy.jsp) ilpFilter field = Sanitize/neutralize input to prevent reflected cross-site script injection (e.g., prevent script-tag injection)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21904?
CVE-2026-21904 has a medium severity rating of 5.1.
What type of vulnerability is CVE-2026-21904?
CVE-2026-21904 is a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-21904?
To resolve CVE-2026-21904, upgrade to Junos Space 24.1R5 Patch V3 or any subsequent release.
Who is affected by CVE-2026-21904?
CVE-2026-21904 affects users of Juniper Networks Junos Space software.
What can an attacker do with CVE-2026-21904?
An attacker can use CVE-2026-21904 to inject script tags that allow them to execute commands on behalf of another user.