CVE-2026-47718
FUXA provides guest and invalid-token access to protected read APIs in secure mode
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.
| CWE | CWE-287 CWE-862 |
| Vendor | frangoteam |
| Product | fuxa |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for frangoteam fuxa
Be the first to know when new unknown vulnerabilities affecting frangoteam fuxa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
frangoteam / FUXA
= 1.3.0-2773