Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q3w6-q3hc-c5x6 | FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations |
Wed, 12 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frangoteam
Frangoteam fuxa |
|
| Vendors & Products |
Frangoteam
Frangoteam fuxa |
Wed, 12 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue. | |
| Title | FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T22:18:04.321Z
Reserved: 2026-05-19T21:29:25.482Z
Link: CVE-2026-47717
No data.
Status : Received
Published: 2026-08-12T23:17:20.643
Modified: 2026-08-12T23:17:20.643
Link: CVE-2026-47717
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:15:03Z
Github GHSA