CVE-2026-26234
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.50%
- CWE
- CWE-644
- Published
- 2026-02-12
- Last modified
- 2026-03-12
Affected products
- ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server
- ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server
- ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server
- ALBRECHT JUNG GMBH & CO. KG JUNG Smart Visu Server
Weakness type
Related vulnerabilities
- CVE-2026-69183 — Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)
- CVE-2026-67179 — Genkit improper host header validation
- CVE-2026-66778 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)
- CVE-2026-72574 — picocms Pico - Host Header Injection Enables Script Source Hijacking
- CVE-2026-0516 — A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow...
- CVE-2026-48061 — Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- CVE-2026-21762 — Missing HTTP Security Headers in DevOps Loop
- CVE-2026-54477 — Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax