High severity8.8NVD Advisory· Published Feb 12, 2026· Updated Jun 17, 2026
CVE-2026-26234
CVE-2026-26234
Description
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:jung-group:smart_visu_server_firmware:*:*:*:*:*:*:*:*Range: >=1.0.830,<=1.1.1050
- Range: <=1.1.1050
- ALBRECHT JUNG GMBH & CO. KG/JUNG Smart Visu Serverv5Range: 1.1.1050
Patches
Vulnerability mechanics
References
2- www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5970.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/jung-smart-visu-server-improper-neutralization-of-http-headers-for-scripting-syntaxnvdThird Party Advisory
News mentions
0No linked articles in our index yet.