Junglewise Threat Intelligence

CVE-2026-72586: frangoteam FUXA missing authentication in DAQ_QUERY handler

CVE-2026-72586 · Severity: high · CVSS 7.5 · Published 2026-08-10

Technologies: Frangoteam FUXA. Vendors: Frangoteam.

Executive brief

FUXA is a web-based SCADA/HMI visualization software used to monitor and control industrial processes. An unauthenticated attacker can query all historical sensor data by exploiting a missing authentication check in the DAQ_QUERY Socket.IO event, bypassing the security controls that protect other sensitive operations when security is enabled.

Technical details

FUXA contains an authentication bypass vulnerability in the DAQ_QUERY Socket.IO event handler located in server/runtime/index.js. While other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) correctly call isSocketAdminAuthorized to verify connection tokens when secureEnabled=true, the DAQ_QUERY handler entirely lacks this authentication check. An unauthenticated remote attacker can connect via Socket.IO and invoke DAQ_QUERY to retrieve historical sensor data without credentials. The vulnerability affects FUXA through version 1.3.3 and requires network access to the Socket.IO endpoint but no user interaction or authentication.

Affected products

  • frangoteam FUXA through 1.3.3

Timeline

  • 2026-08-10: disclosed

References

Related threats