CVE-2026-47718

Summary

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When secureEnabled=true, FUXA 1.3.0-2773 still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

Affected Software

VendorProductVersion RangeStatus
frangoteamFUXA= 1.3.0-2773affected

Weaknesses

  • CWE-287: CWE-287: Improper Authentication
  • CWE-862: CWE-862: Missing Authorization

References