๐Ÿ” CVE Alert

CVE-2026-43946

UNKNOWN 0.0

FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

CWE CWE-863
Vendor frangoteam
Product fuxa
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new unknown vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frangoteam / FUXA
= 1.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-fwcm-rqvw-j3p7 github.com: https://github.com/frangoteam/FUXA/pull/2260 github.com: https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4 github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.1