Request Header Manipulation Vulnerability in JUNG Smart Visu Server
CVE-2026-26234
8.7HIGH
What is CVE-2026-26234?
JUNG Smart Visu Server versions prior to 1.1.1050 are susceptible to a request header manipulation vulnerability. This flaw allows unauthenticated attackers to tamper with request URLs by injecting malicious values into the X-Forwarded-Host header. Consequently, attackers can manipulate proxied requests, leading to cache poisoning and potentially redirecting users to malicious sites. This misconfiguration poses severe security risks, including phishing attempts aimed at unsuspecting users.
Affected Version(s)
JUNG Smart Visu Server 1.1.1050
JUNG Smart Visu Server 1.0.905
JUNG Smart Visu Server 1.0.832
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
