Authorization Bypass in FUXA SCADA/HMI Software by Frango Team
CVE-2026-25939

9.3CRITICAL

Key Information:

Vendor

Frangoteam

Status
Vendor
CVE Published:
9 February 2026

What is CVE-2026-25939?

The FUXA software, a web-based Process Visualization solution, is affected by an authorization bypass vulnerability that enables remote attackers, without authentication, to create and modify arbitrary schedulers. This vulnerability poses significant risks to connected Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments by potentially allowing unauthorized manipulation of critical scheduling functions. Users are encouraged to update to version 1.2.11, where the vulnerability has been patched.

Affected Version(s)

FUXA < 1.2.11

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.