CVE-2026-25939
CRITICALFrangoteam Fuxa < 1.2.11 - Missing Authorization
Title source: ruleDescription
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.
Exploits (2)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25939
nomisec
WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary
Scores
CVSS v3
9.1
EPSS
0.0002
EPSS Percentile
3.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Classification
CWE
CWE-862
Status
published
Affected Products (2)
frangoteam/fuxa
< 1.2.11
npm/fuxa-server
< 1.2.11npm
Timeline
Published
Feb 09, 2026
Tracked Since
Feb 18, 2026