๐Ÿ” CVE Alert

CVE-2026-47721

MEDIUM 6.3

FUXA: Scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin operator can create or alter deviceActions that invoke onSetValue or onRunScript, or delete schedules, gaining access to device-value changes and server-side project script execution normally reserved for administrators. Scheduled and repeating actions can continue changing PLC setpoints, safety interlocks, device state, or project data after the operator's session ends. This issue is fixed in version 1.3.2.

CWE CWE-862
Vendor frangoteam
Product fuxa
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new medium vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

frangoteam / FUXA
< 1.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-8ghr-w65f-j3qr github.com: https://github.com/frangoteam/FUXA/pull/2345 github.com: https://github.com/frangoteam/FUXA/commit/3c945a03f9942fd45a793ab7e3c2d1f1b15b93bf github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.2