CVE-2026-43946
Received Received - Intake

Authorization Bypass in FUXA Web SCADA Software

Vulnerability report for CVE-2026-43946, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: GitHub, Inc.

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
fuxa fuxa to 1.3.1 (exc)
fuxa fuxa 1.3.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FUXA versions up to 1.3.0 have an authorization bypass vulnerability in the /api/getTagValue endpoint. This allows unauthenticated users to access tag values when the referenced script does not exist. The issue is patched in version 1.3.1.

Detection Guidance

Check if your FUXA version is 1.3.0 or earlier by inspecting the software version or logs. Test the /api/getTagValue endpoint by sending a request to see if unauthorized tag values are accessible without authentication.

Impact Analysis

An attacker could exploit this to read sensitive data from the system without authentication. This may lead to unauthorized access to process data, configuration details, or other confidential information stored in the SCADA/HMI system.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may face compliance violations, potential fines, and reputational damage due to data exposure.

Mitigation Strategies

Upgrade FUXA to version 1.3.1 or later immediately to patch the authorization bypass. If upgrading is not possible, restrict network access to the /api/getTagValue endpoint and monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-43946. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart