CVE-2026-26234: Jung-Group Smart Visu Server Firmware
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.
Affected products
- Jung-Group Smart Visu Server Firmware: from 1.0.830, up to and including 1.1.1050
Published 2026-02-12. Last modified 2026-06-17.