What is CVE-2026-43946?
CVE-2026-43946 is an authorization bypass vulnerability in the /api/getTagValue endpoint of FUXA v1.3.0, a web-based SCADA/HMI software. It allows unauthenticated access to tag values when the referenced script does not exist. Upgrading to version 1.3.1 resolves the issue.
Azərbaycanca: CVE-2026-43946 FUXA v1.3.0 versiyasında /api/getTagValue endpoint-də authorization bypass zəifliyidir. Bu, mövcud olmayan skriptə istinad edildikdə autentifikasiya olunmadan tag dəyərlərinə giriş imkanı yaradır. 1.3.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which FUXA version is affected by CVE-2026-43946?
FUXA version 1.3.0 is affected.
How can CVE-2026-43946 be resolved?
Upgrading FUXA to version 1.3.1 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.