Request Header Manipulation Vulnerability in JUNG Smart Visu Server
CVE-2026-26234

8.7HIGH

Key Information:

Vendor
CVE Published:
12 February 2026

What is CVE-2026-26234?

JUNG Smart Visu Server versions prior to 1.1.1050 are susceptible to a request header manipulation vulnerability. This flaw allows unauthenticated attackers to tamper with request URLs by injecting malicious values into the X-Forwarded-Host header. Consequently, attackers can manipulate proxied requests, leading to cache poisoning and potentially redirecting users to malicious sites. This misconfiguration poses severe security risks, including phishing attempts aimed at unsuspecting users.

Affected Version(s)

JUNG Smart Visu Server 1.1.1050

JUNG Smart Visu Server 1.0.905

JUNG Smart Visu Server 1.0.832

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.