Missing Authentication Vulnerability in FrangoTeam FUXA
CVE-2026-72586

7.5HIGH

Key Information:

Vendor

Frangoteam

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72586?

A missing authentication vulnerability exists in FrangoTeam's FUXA, which allows unauthenticated remote attackers to query all historical sensor data through the DAQ_QUERY Socket.IO event. In scenarios where secureEnabled=true, while other sensitive Socket.IO events employ the isSocketAdminAuthorized method to validate connection tokens, the DAQ_QUERY handler in server/runtime/index.js does not perform this authorization check. As a result, this flaw exposes critical sensor data, posing serious implications for data integrity and confidentiality. Users of affected versions should review their configurations and update to the latest version to mitigate this issue.

Affected Version(s)

FUXA 0 <= 1.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naimov Muhammad
.