Project Subscriptions
No data.
No advisories yet.
Solution
Frangoteam recommends users apply the latest version of FUXA 1.3.2 or later https://github.com/frangoteam/FUXA/releases. https://github.com/frangoteam/FUXA/releases
Workaround
No workaround given by the vendor.
Tue, 30 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticated requests to access protected endpoints by prefixing paths with dot-segments such as /api/./users, /api/./roles, and /api/project/../users. These requests bypass authentication checks and return sensitive user and role data without credentials. | |
| Title | Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-30T20:24:33.449Z
Reserved: 2026-06-24T14:31:56.877Z
Link: CVE-2026-13207
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T22:30:06Z