CVE-2026-47717

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

Scoring

Severity
HIGH
CVSS base score
7.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS probability
1.20%
CWE
CWE-201
Published
2026-08-12
Last modified
2026-08-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs