PT-2026-47618 · Fuxa · Fuxa

CVE-2026-47721

·

Published

2026-06-08

·

Updated

2026-08-19

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FUXA versions prior to 1.3.2
Description An authorization bypass exists in the Scheduler API where the system fails to consistently enforce administrator permissions. An authenticated non-admin operator can create or modify deviceActions that invoke onSetValue or onRunScript, or delete existing schedules. This allows unauthorized access to device-value changes and server-side project script execution, which are privileges normally reserved for administrators. In SCADA deployments, this can lead to unauthorized control of PLC setpoints, safety interlocks, and device states. Because these actions can be scheduled or repeated, they may continue to execute and modify project data even after the operator's session has ended.
The issue affects the following API endpoints:
  • 'POST /api/scheduler'
  • 'DELETE /api/scheduler'
Recommendations Update FUXA to version 1.3.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47721
GHSA-8GHR-W65F-J3QR

Affected Products

Fuxa