nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-26234 CVE-2026-26234
HIGH
JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax
Record summary
CVE-2026-26234 has a selected CVSS score of 8.7 (high).
Description
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
JUNG Smart Visu ServerBrowse ALBRECHT JUNG GMBH & CO. KG / JUNG Smart Visu Server | CVE List | 1.1.1050 | affected |
| 1.0.905 | affected | ||
| 1.0.832 | affected | ||
| 1.0.830 | affected |
References
3VulnCheck Advisory: JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting SyntaxThird-party advisory
https://www.vulncheck.com/advisories/jung-smart-visu-server-improper-neutralization-of-http-headers-for-scripting-syntax Zero Science Lab Vulnerability AdvisoryThird-party advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5970.php