CVE 8.7 HIGH

JUNG Smart Visu Server – Improper Neutralization of HTTP Headers for Scripting Syntax_CVE-2026-26234

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.

AI Analysis

Request header manipulation vulnerability allowing unauthenticated attackers to override request URLs and potentially enable cache poisoning, phishing, and redirecting users to malicious domains

Basic Information

ID CVE-2026-26234
Source VulnCheck
Published Feb 12, 2026 at 02:31

Affected Product

Vendor ALBRECHT JUNG GMBH & CO. KG
Product JUNG Smart Visu Server
Version 1.1.1050
Affected Versions ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server 1.1.1050
ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server 1.0.905
ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server 1.0.832
ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server 1.0.830

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor ALBRECHT JUNG GMBH & CO. KG
Product JUNG Smart Visu Server
Version 1.1.1050, 1.0.905, 1.0.832, 1.0.830

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.