PT-2026-44733 · Fuxa · Fuxa

CVE-2026-47718

·

Published

2026-05-28

·

Updated

2026-08-14

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FUXA version 1.3.0-2773
Description FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authentication bypass exists when secureEnabled is set to true, allowing guests or users with invalid tokens to access protected read APIs. This occurs because the verifyToken() function in server/api/jwt-helper.js converts missing or invalid tokens into a guest context rather than rejecting the request. Consequently, the following API endpoints are accessible without valid authentication, leading to the disclosure of project metadata, alarms, and scheduler information:
  • '/api/project'
  • '/api/alarms'
  • '/api/scheduler'
Recommendations Update FUXA to version 1.3.1.

Exploit

Fix

Improper Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47718
GHSA-R9G5-7Q8J-958C

Affected Products

Fuxa