CVE-2026-26234
EUVD-2026-702812.02.2026, 04:15
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jung-group | smart_visu_server_firmware | 1.0.830 ≤ 𝑥 ≤ 1.1.1050 |
𝑥
= Vulnerable software versions