HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
Published Jul 21, 2026
8.9
HIGHCVSS 4.0
EPSS 0.84%
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.
Affected products
-
- Version >= 1.2.11, < 1.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Frangoteam | FUXA | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
@frangoteam/fuxa
npm
Introduced 1.2.11 Fixed 1.3.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @frangoteam/fuxa | 1.2.11 | 1.3.1 |
Remediation
No remediation recorded yet.
Weaknesses (4)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46441 Advisory
- https://github.com/advisories/GHSA-p69w-mmfv-xrfj Advisory
- https://github.com/frangoteam/FUXA/releases/tag/v1.3.1 x_refsource_MISC
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-p69w-mmfv-xrfj x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46441 | Advisory | |
| https://github.com/advisories/GHSA-p69w-mmfv-xrfj | Advisory | |
| https://github.com/frangoteam/FUXA/releases/tag/v1.3.1 | x_refsource_MISC | |
| https://github.com/frangoteam/FUXA/security/advisories/GHSA-p69w-mmfv-xrfj | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 21, 2026
Updated Jul 22, 2026
Reserved May 4, 2026
Link CVE-2026-43945
CISA Vulnrichment
Updated Jul 22, 2026
ENISA EUVD
EUVD-2026-46441 GHSA-P69W-MMFV-XRFJ Assigner GitHub_M
Published Jul 21, 2026
Updated Jul 22, 2026
Exploited since n/a
Link EUVD-2026-46441