Insecure Default Configuration in FUXA Web-Based Process Visualization Software
CVE-2026-25894
9.5CRITICAL
What is CVE-2026-25894?
FUXA, a web-based Process Visualization software, suffers from an insecure default configuration that permits unauthenticated remote attackers to gain administrative access and execute arbitrary code. This vulnerability exists in versions up to 1.2.9 where authentication is enabled but the administrator JWT secret is not properly configured. A patch has been released in version 1.2.10 to resolve this issue. Users are strongly advised to upgrade to the latest version to mitigate potential risks.
Affected Version(s)
FUXA < 1.2.10
