Junglewise Threat Intelligence

CVE-2026-25939: FUXA authorization bypass in scheduler endpoint

CVE-2026-25939 · Severity: medium · CVSS 4 · Published 2026-02-10

Technologies: Frangoteam FUXA, fuxa-server (npm). Vendors: Frangoteam, npm.

Executive brief

FUXA is an industrial control and SCADA visualization platform used to monitor and control connected devices and infrastructure. An unauthenticated attacker can bypass authorization checks to create, modify, or delete schedules that automatically execute actions on connected industrial equipment—potentially forcing devices into unsafe states or executing malicious commands without any authentication requirement.

Technical details

This is an authorization bypass vulnerability (CWE-862) in FUXA's scheduler endpoint that allows unauthenticated, remote attackers to automatically authenticate as guest and manipulate scheduling rules. The attack requires no network authentication, credentials, or user interaction—only network reachability to the FUXA service. An attacker can create or modify schedules to trigger immediately or cyclically, forcing connected ICS/SCADA devices to specific states or executing existing scripts on the server. This affects versions 1.2.8 through 1.2.10; the vulnerability has been patched in version 1.2.11.

Affected products

  • Frangoteam FUXA 1.2.8 through 1.2.10

Timeline

  • 2026-02-09: disclosed: Advisory published on GitHub
  • 2026-02-10: patched: Fixed in version 1.2.11

References

Related threats