๐Ÿ” CVE Alert

CVE-2026-43947

UNKNOWN 0.0

FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against the stored script's permission by ID, but when `test: true` is set in the request, it compiles and executes attacker-supplied code instead of the stored script's code. An unauthenticated attacker who knows a valid script ID and name may execute arbitrary code via test mode if at least one server-side script exists and is accessible without restrictive permissions. Script IDs and names can be obtained through the unauthenticated information disclosure in `GET /api/project` (reported separately). The only prerequisite is that at least one server-side script exists in the project. Version 1.3.1 fixes the issue.

CWE CWE-863
Vendor frangoteam
Product fuxa
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new unknown vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frangoteam / FUXA
= 1.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-rg3m-cfq7-g6h6 github.com: https://github.com/frangoteam/FUXA/pull/2260 github.com: https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4 github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.1