Access Control Vulnerability in FUXA Process Visualization Software
CVE-2026-47718

5.5MEDIUM

Key Information:

Vendor

Frangoteam

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-47718?

FUXA, a web-based Process Visualization software, has a vulnerability that permits unauthorized access to project, alarms, and scheduler APIs even when secured settings are enabled. Specifically, when 'secureEnabled=true', the software does not correctly handle guest and invalid-token requests, potentially exposing sensitive data. This issue affects version 1.3.0-2773 and has been addressed in version 1.3.1.

Affected Version(s)

FUXA = 1.3.0-2773

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.