PT-2026-44163 · Npm · Fuxa-Server

CVE-2026-47717

·

Published

2026-05-27

·

Updated

2026-06-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FUXA version 1.3.0
Description The '/api/project' endpoint exposes sensitive SCADA/HMI project configuration data to unauthenticated requests. This occurs because the secureFnc middleware utilizes a function that automatically generates a valid guest JWT when no token is provided. Consequently, the getProject() function returns full project data. While some UI elements are filtered for non-admin users, sensitive information remains exposed, including server-side scripts (source code, IDs, and names), device configurations, communication endpoint information, HMI views (SVG content and variable bindings), and alarm definitions. In industrial environments, this disclosure of internal automation logic and project structure can facilitate targeted attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/api/project' endpoint to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47717
GHSA-Q3W6-Q3HC-C5X6

Affected Products

Fuxa-Server