Unrated severityNVD Advisory· Published Feb 12, 2026· Updated Mar 5, 2026
JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-26234
Description
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
Affected products
2- Range: = 1.0.1050
- ALBRECHT JUNG GMBH & CO. KG/JUNG Smart Visu Serverv5Range: 1.1.1050
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vulncheck.com/advisories/jung-smart-visu-server-improper-neutralization-of-http-headers-for-scripting-syntaxmitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5970.phpmitrethird-party-advisory
News mentions
0No linked articles in our index yet.