Missing Authentication Vulnerability in FrangoTeam FUXA
CVE-2026-72586
7.5HIGH
What is CVE-2026-72586?
A missing authentication vulnerability exists in FrangoTeam's FUXA, which allows unauthenticated remote attackers to query all historical sensor data through the DAQ_QUERY Socket.IO event. In scenarios where secureEnabled=true, while other sensitive Socket.IO events employ the isSocketAdminAuthorized method to validate connection tokens, the DAQ_QUERY handler in server/runtime/index.js does not perform this authorization check. As a result, this flaw exposes critical sensor data, posing serious implications for data integrity and confidentiality. Users of affected versions should review their configurations and update to the latest version to mitigate this issue.
Affected Version(s)
FUXA 0 <= 1.3.3
