CVE-2026-43946

Published: Lug 21, 2026 Last Modified: Lug 21, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.