PT-2026-77307 · Fuxa · Fuxa

CVE-2026-67442

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

2.0

Low

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FUXA versions prior to 1.3.3
Description FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. The application fails to fully remove role identifiers from the info.roles array of users or the runtime usersMap cache when a role is deleted via the 'DELETE /api/roles' endpoint through server/runtime/users/usrstorage.js. If a permission configuration continues to reference the deleted identifier, users may retain authorization rights that were intended to be revoked, leading to residual privileges, an inconsistent access-control state, and misleading audit results.
Recommendations Update to version 1.3.3.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67442
GHSA-CQWW-JQX5-P32V

Affected Products

Fuxa