CVE-2026-67442
FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup
CVSS Score
2.0
EPSS Score
0.0%
EPSS Percentile
0th
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration still references that identifier, an affected user can retain authorization rights that an administrator intended to revoke, causing residual privilege, inconsistent access-control state, and misleading audit results. This issue is fixed in version 1.3.3.
| CWE | CWE-284 CWE-459 |
| Vendor | frangoteam |
| Product | fuxa |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for frangoteam fuxa
Be the first to know when new low vulnerabilities affecting frangoteam fuxa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
frangoteam / FUXA
< 1.3.3
References
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-cqww-jqx5-p32v github.com: https://github.com/frangoteam/FUXA/pull/2394 github.com: https://github.com/frangoteam/FUXA/commit/7ce84dc29a691b30016d65db17012bb8b282dcf0 github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.3