CVE-2026-43946

Summary

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

Affected Software

VendorProductVersion RangeStatus
frangoteamFUXA= 1.3.0affected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

References