PT-2026-77304 · Fuxa · Fuxa
CVE-2026-65984
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FUXA versions prior to 1.3.3
Description
FUXA is a web-based Process Visualization software. The application fails to properly validate current database records during session renewal. Specifically, the endpoint '/api/refresh' in server/api/auth/index.js falls back to
decoded.groups instead of current user data, and the endpoint '/api/heartbeat' in server/api/index.js re-signs inbound JSON Web Token (JWT) claims without verification. This allows an attacker with a previously issued privileged refresh cookie or access token to continue generating privileged JWTs even after an account has been deleted, disabled, or had its roles removed. This can lead to unauthorized access to user management, project manipulation, runtime configuration, scripts, and the creation of backdoor accounts.Recommendations
Update to version 1.3.3.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuxa