Vulnerability Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.
Related Weaknesses (CWE)
References
- https://github.com/frangoteam/FUXA/releases/tag/v1.3.1
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-r9g5-7q8j-958c
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-r9g5-7q8j-958c
FAQ
What is CVE-2026-47718?
CVE-2026-47718 is a documented vulnerability. FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and schedu...
How severe is CVE-2026-47718?
CVSS scoring is not yet available for CVE-2026-47718. Check NVD for updates.
Is there a patch for CVE-2026-47718?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.