CVE-2026-25939

CRITICAL

Frangoteam Fuxa < 1.2.11 - Missing Authorization

Title source: rule

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25939
nomisec WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary

Scores

CVSS v3 9.1
EPSS 0.0002
EPSS Percentile 3.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-862
Status published

Affected Products (2)

frangoteam/fuxa < 1.2.11
npm/fuxa-server < 1.2.11npm

Timeline

Published Feb 09, 2026
Tracked Since Feb 18, 2026