CVE-2026-26234Disclosure(jung-group / smart_visu_server)

LOWCVSS 8.7 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch jung-group smart_visu_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential phishing, and redirecting users to malicious domains.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-644

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smart_visu_server
  • smart_visu_server_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
smart_visu_serversmart_visu_server_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-12: 5Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 402-12
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26234 Request Header Manipulation in JUNG Smart Visu Server 1.1.1050 Enables URL Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26234

    Post summary

    The text announces CVE-2026-26234, noting a request header manipulation that enables URL injection in JUNG Smart Visu Server 1.1.1050, but it provides no PoC, exploit, active exploitation, or patch details.

    0001038
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: CVE-2026-26234 in JUNG Smart Visu Server lets unauth'd attackers hijack X-Forwarded-Host header for cache poisoning & phishing. Patch ASAP & restrict access! https://radar.offseq.com/threat/cve-2026-26234-improper-neutralization-of-http-hea-13dc0f5b #OffSeq #C... https://t.co/JwGZ2PS2If

    Post summary

    The tweet announces a high‑severity CVE‑2026‑26234 that enables unauthenticated attackers to hijack the X‑Forwarded‑Host header for cache poisoning and phishing, and urges immediate patching and access restriction.

    0000045
    268 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26234: HIGH] Vulnerability in JUNG Smart Visu Server 1.1.1050 allows attackers to manipulate requests via X-Forwarded-Host header, leading to potential cyber threats like cache poisoning and phishi...#cve,CVE-2026-26234,#cybersecurity https://cvefind.com/CVE-2026-26234

    Post summary

    The tweet discloses CVE‑2026‑26234, stating that JUNG Smart Visu Server 1.1.1050 is vulnerable to X‑Forwarded‑Host header manipulation which could lead to cache poisoning or phishing, with no PoC, exploit, or patch information provided.

    0000050
    583 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-26234 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-26234 #CVE-2026-26234 #CVE #High #CyberSecurity #InfoSec https://t.co/RGuZYKZLnB

    Post summary

    The tweet announces the new CVE-2026-26234 with severity 8.8 and high risk but provides no further technical details, PoC, or exploitation information.

    0000062
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26234 JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbit… https://www.cve.org/CVERecord?id=CVE-2026-26234

    Post summary

    The entry announces a request‑header manipulation flaw in JUNG Smart Visu Server 1.1.1050 that permits unauthenticated URL overriding. No PoC, exploit, or patch details are provided.

    00000121
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWjung-groupsmart_visu_server---
OSjung-groupsmart_visu_server_firmware---

Explore more