CVE-2026-43946
HIGH
7.7
CVSS 4.0
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.
Metadata
Severity & Metrics
7.7
HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| frangoteam | FUXA | — | = 1.3.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-863 | cna | CWE-863: Incorrect Authorization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.7 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
References (4)
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-fwcm-rqvw-j3p7 https://github.com/frangoteam/FUXA/security/advisories/GHSA-fwcm-rqvw-j3p7
- https://github.com/frangoteam/FUXA/pull/2260 https://github.com/frangoteam/FUXA/pull/2260
- https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4 https://github.com/frangoteam/FUXA/commit/78534da61a91613712b44bb63c8d7da8c5df5ca4
- https://github.com/frangoteam/FUXA/releases/tag/v1.3.1 https://github.com/frangoteam/FUXA/releases/tag/v1.3.1