๐Ÿ” CVE Alert

CVE-2026-65984

UNKNOWN 0.0

FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, and POST /api/heartbeat in server/api/index.js re-signs inbound JWT claims without validating the current database record. An attacker who possesses a previously issued privileged refresh cookie or access token can continue minting privileged JWTs after account deletion, disablement, role removal, or demotion. Continued refresh-cookie rotation can extend the stale session and preserve unauthorized access to user management, project manipulation, runtime configuration, scripts, and backdoor-account creation. This issue is fixed in version 1.3.3.

CWE CWE-613
Vendor frangoteam
Product fuxa
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new unknown vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frangoteam / FUXA
< 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-rg7m-xwqc-mjw6 github.com: https://github.com/frangoteam/FUXA/pull/2379 github.com: https://github.com/frangoteam/FUXA/commit/4fa47d0a2a856ed34f427f472fb4450f86e7749b github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.3