PT-2026-53986 · Fuxa · Fuxa
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FUXA versions prior to 1.3.2
Description
An authentication bypass exists in the REST API due to improper dot-segment path normalization. The API router does not normalize dot-segment sequences before the authentication middleware is applied. This allows unauthenticated users to access protected endpoints by prefixing paths with dot-segments, such as '/api/./users', '/api/./roles', and '/api/project/../users', resulting in the unauthorized disclosure of sensitive user and role data.
Recommendations
Update FUXA to version 1.3.2 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuxa