CVE-2026-26234

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:jung-group:smart_visu_server_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:jung-group:smart_visu_server:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-12 04:15

Updated : 2026-02-20 15:14


NVD link : CVE-2026-26234

Mitre link : CVE-2026-26234

CVE.ORG link : CVE-2026-26234


JSON object : View

Products Affected

jung-group

  • smart_visu_server_firmware
  • smart_visu_server
CWE
CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax