PT-2026-69470 · Frangoteam · Fuxa

·

CVE-2026-72586

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions frangoteam/FUXA versions prior to 1.3.4
Description A missing authentication flaw allows an unauthenticated remote attacker to query all historical sensor data. This occurs because the DAQ QUERY Socket.IO event handler in server/runtime/index.js does not call the isSocketAdminAuthorized() function to verify the connection token, even when secureEnabled is set to true. Other sensitive Socket.IO events, such as DEVICE BROWSE, HOST INTERFACES, and DEVICE TAGS REQUEST, correctly implement this authorization check.
Recommendations Update frangoteam/FUXA to version 1.3.4 or later. As a temporary mitigation, restrict access to the DAQ QUERY Socket.IO event.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72586

Affected Products

Fuxa