Junglewise Threat Intelligence

CVE-2026-65984: FUXA session fixation via stale JWT refresh

CVE-2026-65984 · Severity: info · CVSS 7.5 · Published 2026-08-18

Technologies: FUXA Team FUXA.

Executive brief

FUXA is web-based SCADA/HMI software used to visualize and control industrial processes. In versions 1.3.2 and earlier, an attacker with a previously issued privileged access token can continue to mint new valid authentication tokens even after their account is deleted, disabled, or demoted. This allows indefinite unauthorized access to system administration functions including user management, project configuration, script execution, and backdoor account creation.

Technical details

The vulnerability exists in POST /api/refresh and POST /api/heartbeat endpoints where JWT token validation and refresh operations fail to verify the current state of the user account against the database. The refresh endpoint falls back to stale group claims from previously issued tokens even when the user record no longer exists or roles have been revoked. The heartbeat endpoint re-signs JWT claims without validating the current user record state. An attacker in possession of a valid refresh token or access token can exploit this to mint new privileged JWTs indefinitely, bypassing access control enforcement. No special authentication or user interaction is required beyond possessing a valid token. The fix is available in version 1.3.3.

Affected products

  • FUXA Team FUXA 1.3.2 and earlier

Timeline

  • 2026-08-18: disclosed
  • 2026-05-25: patched: Fixed in version 1.3.3

References