AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47718

MEDIUM · CVSS 5.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

FUXA version 1.3.0-2773 is vulnerable as it permits unauthorized access to project, alarms, and scheduler APIs even when `secureEnabled=true`, allowing guest and invalid-token requests. This could lead to exposure of sensitive operational data, potentially compromising system integrity and confidentiality. Organizations using this version of FUXA should prioritize upgrading to version 1.3.1 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47718
Severity
MEDIUM
CVSS
5.5
EPSS
0.27%

Original NVD Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.