Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fwcm-rqvw-j3p7 | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue |
Wed, 22 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue. | |
| Title | FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-22T15:02:58.663Z
Reserved: 2026-05-04T16:59:09.090Z
Link: CVE-2026-43946
Updated: 2026-07-22T15:02:54.288Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA