PT-2026-47618 · Fuxa · Fuxa
CVE-2026-47721
·
Published
2026-06-08
·
Updated
2026-08-19
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
FUXA versions prior to 1.3.2
Description
An authorization bypass exists in the Scheduler API where the system fails to consistently enforce administrator permissions. An authenticated non-admin operator can create or modify
deviceActions that invoke onSetValue or onRunScript, or delete existing schedules. This allows unauthorized access to device-value changes and server-side project script execution, which are privileges normally reserved for administrators. In SCADA deployments, this can lead to unauthorized control of PLC setpoints, safety interlocks, and device states. Because these actions can be scheduled or repeated, they may continue to execute and modify project data even after the operator's session has ended.The issue affects the following API endpoints:
- 'POST /api/scheduler'
- 'DELETE /api/scheduler'
Recommendations
Update FUXA to version 1.3.2.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuxa