CVE-2026-26234

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
12/02/2026
Last modified:
20/02/2026

Description

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:jung-group:smart_visu_server_firmware:*:*:*:*:*:*:*:* 1.0.830 (including) 1.1.1050 (including)
cpe:2.3:h:jung-group:smart_visu_server:-:*:*:*:*:*:*:*