Junglewise Threat Intelligence

CVE-2026-43946: frangoteam FUXA authorization bypass in /api/getTagValue

CVE-2026-43946 · Severity: high · CVSS 4 · Published 2026-07-21

Technologies: Frangoteam FUXA, fuxa-server (npm). Vendors: Frangoteam, npm.

Executive brief

FUXA is a web-based industrial automation platform used for monitoring and controlling industrial processes (SCADA/HMI). A security flaw in version 1.3.0 allows unauthorized individuals to view sensitive operational data, known as 'tag values,' without logging in. This could allow an attacker to monitor real-time industrial processes or harvest proprietary operational data, potentially compromising the confidentiality of the facility's operations.

Technical details

An authorization bypass exists in FUXA version 1.3.0 within the /api/getTagValue endpoint. The vulnerability stems from a logic error where the system automatically assigns a 'guest' token to unauthenticated requests and the authorization check function, isAuthorisedByScriptName(), incorrectly returns 'true' if a referenced script name is missing or non-existent. An attacker can exploit this by sending specially crafted network requests to the API without any credentials to retrieve arbitrary tag values by ID. This issue is resolved in version 1.3.1 by hardening the request routing logic and authorization validation.

Affected products

  • frangoteam FUXA 1.3.0

Timeline

  • 2026-03-19: patched: Fix merged into master branch
  • 2026-04-09: patched: Official release of version 1.3.1
  • 2026-05-19: advisory: GitHub Security Advisory published
  • 2026-07-21: disclosed: CVE published to NVD

References

Related threats