PT-2026-77304 · Fuxa · Fuxa

CVE-2026-65984

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FUXA versions prior to 1.3.3
Description FUXA is a web-based Process Visualization software. The application fails to properly validate current database records during session renewal. Specifically, the endpoint '/api/refresh' in server/api/auth/index.js falls back to decoded.groups instead of current user data, and the endpoint '/api/heartbeat' in server/api/index.js re-signs inbound JSON Web Token (JWT) claims without verification. This allows an attacker with a previously issued privileged refresh cookie or access token to continue generating privileged JWTs even after an account has been deleted, disabled, or had its roles removed. This can lead to unauthorized access to user management, project manipulation, runtime configuration, scripts, and the creation of backdoor accounts.
Recommendations Update to version 1.3.3.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65984
GHSA-RG7M-XWQC-MJW6

Affected Products

Fuxa