Vulnerability Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frangoteam | Fuxa | >= 1.2.8, < 1.2.11 |
Related Weaknesses (CWE)
References
- https://github.com/frangoteam/FUXA/commit/5782b35117a9bd14ffcb881f8dfb8c6680157dPatch
- https://github.com/frangoteam/FUXA/releases/tag/v1.2.11Release Notes
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-c869-jx4c-q5fcVendor Advisory
FAQ
What is CVE-2026-25939?
CVE-2026-25939 is a vulnerability with a CVSS score of 9.1 (CRITICAL). FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attack...
How severe is CVE-2026-25939?
CVE-2026-25939 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-25939?
Check the references section above for vendor advisories and patch information. Affected products include: Frangoteam Fuxa.