๐Ÿ” CVE Alert

CVE-2026-67442

LOW 2.0

FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup

CVSS Score
2.0
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration still references that identifier, an affected user can retain authorization rights that an administrator intended to revoke, causing residual privilege, inconsistent access-control state, and misleading audit results. This issue is fixed in version 1.3.3.

CWE CWE-284 CWE-459
Vendor frangoteam
Product fuxa
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new low vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

frangoteam / FUXA
< 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-cqww-jqx5-p32v github.com: https://github.com/frangoteam/FUXA/pull/2394 github.com: https://github.com/frangoteam/FUXA/commit/7ce84dc29a691b30016d65db17012bb8b282dcf0 github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.3