github.com
https://github.com/frangoteam/FUXA CVE-2026-47718
MEDIUM
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Record summary
CVE-2026-47718 has a selected CVSS score of 5.5 (medium).
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | = 1.3.0-2773 | affected | |
fuxa-serverBrowse npm / fuxa-server | GitHub Advisory | 1.3.0-2773 | affected |
| 1.3.0-2773 to < 1.3.1 · Fixed in 1.3.1 | affected |
References
3github.com
https://github.com/frangoteam/FUXA/releases/tag/v1.3.1 github.comConfirmation
https://github.com/frangoteam/FUXA/security/advisories/GHSA-r9g5-7q8j-958c