CVE-2026-47717
Received Received - Intake

FUXA Server Sensitive Project Data Exposure via Guest Request

Vulnerability report for CVE-2026-47717, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: GitHub, Inc.

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fuxa fuxa-server 1.3.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FUXA is a web-based Process Visualization software. In version 1.3.0, the GET /api/project endpoint allows unauthorized access to sensitive project configuration data even when secureEnabled is enabled. This means guest users can retrieve confidential information without proper authentication.

Impact Analysis

This vulnerability allows attackers to access sensitive project configurations without authentication. This could lead to data breaches, unauthorized system access, or manipulation of industrial control systems if the exposed data includes operational details.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) or HIPAA (health information privacy) by exposing sensitive data to unauthorized parties. Organizations using FUXA may face regulatory penalties or legal consequences due to unauthorized data exposure.

Mitigation Strategies

Upgrade FUXA to version 1.3.1 or later to fix the issue where sensitive project configuration data is exposed via the GET /api/project endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart