CVE-2026-47717
published 2026-08-12CVE-2026-47717: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project…
PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
1.40%
71.4th percentile
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| frangoteam | fuxa | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FrangoTeam Fuxa 1.3.0 Project Endpoint information disclosure
vuldb·2026-08-13·CVSS 7.5
CVE-2026-47717 [HIGH] FrangoTeam Fuxa 1.3.0 Project Endpoint information disclosure
A vulnerability marked as problematic has been reported in FrangoTeam Fuxa 1.3.0. This affects an unknown function of the component Project Endpoint. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2026-47717. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
ghsa·2026-05-27
CVE-2026-47717 [HIGH] CWE-201 FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
### Summary
The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled.
### Details
File: `server/api/projects/index.js`
```javascript
prjApp.get("/api/project", secureFnc, function(req, res) {
const permission = checkGroupsFnc(req);
runtime.project.getProject(req.userId, permission).then(result => {
if (result) {
res.json(result);
}
});
});
```
The endpoint uses the `secureFnc` middleware, but this middleware calls `verifyToken` in `server/api/jwt-helper.js` which auto-generates a valid guest JWT when no token is provided (line 49-51):
```javascript
if (!token) {
token = getGuestToken();
}
```
The guest to
No detection rules found.
Nuclei
FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure
nuclei·CVSS 7.5
CVE-2026-47717 FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure
FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure
FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates
a valid guest JWT when no token is provided, bypassing authentication. Exposed data includes server-side scripts, device configs, HMI views, and alarm definitions.
Template:
id: CVE-2026-47717
info:
name: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure
author: pussycat0x
severity: high
description: |
FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates
a valid guest JWT when no token is provided, bypassing authenticat
No writeups or analysis indexed.
2026-08-12
Published