CVE-2026-26235

HIGH

JUNG Smart Visu Server 1.1.1050 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-26235. PoCs published by banyamer, XiaomingX, mbanyamer.

AI-analyzed exploit summary This Python script exploits CVE-2026-26235, a missing authentication vulnerability in JUNG Smart Visu Server, allowing unauthenticated reboot or shutdown via direct POST requests to specific CGI endpoints.

Description

JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication.

Exploits (3)

exploitdb WORKING POC
by banyamer · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52536

This Python script exploits CVE-2026-26235, a missing authentication vulnerability in JUNG Smart Visu Server, allowing unauthenticated reboot or shutdown via direct POST requests to specific CGI endpoints.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: JUNG Smart Visu Server <= 1.1.1050
No auth needed
Prerequisites: network access to the target server
devstral-2 · analyzed May 05, 2026 Full analysis →
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-26235

The repository contains a functional Python exploit for CVE-2026-26235, which targets an unauthenticated remote reboot/shutdown vulnerability in JUNG Smart Visu Server <= 1.1.1050. The exploit sends a POST request to exposed CGI endpoints without authentication, demonstrating the vulnerability.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: JUNG Smart Visu Server <= 1.1.1050
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown

This is a functional PoC exploit for CVE-2026-26235, demonstrating unauthenticated remote reboot/shutdown of JUNG Smart Visu Server via exposed CGI endpoints. The script sends a POST request to either /cgi-bin/reboot.sh or /cgi-bin/shutdown.sh without authentication.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: JUNG Smart Visu Server <= 1.1.1050
No auth needed
Prerequisites: Network access to the target server · Target server running vulnerable JUNG Smart Visu Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0178
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
jung-group/smart_visu_server_firmware < 1.1.1050
Published Feb 12, 2026
Tracked Since Feb 18, 2026