What is CVE-2026-43947?
An unauthenticated Remote Code Execution (RCE) vulnerability has been discovered in FUXA SCADA/HMI software version 1.3.0. The flaw exists because the `POST /api/runscript` endpoint fails to properly validate permissions, even when `secureEnabled` is set to `true`. It is recommended to urgently upgrade FUXA to the latest version or restrict access to the affected endpoint.
Azərbaycanca: FUXA SCADA/HMI proqram təminatının 1.3.0 versiyasında autentifikasiya olunmamış Uzaqdan Kod İcrası (RCE) zəifliyi aşkar edilib. Bu boşluq, `secureEnabled` parametri aktiv olduqda belə, `POST /api/runscript` endpoint-ində səlahiyyət yoxlamasının düzgün aparılmaması səbəbindən yaranır. Təcili olaraq FUXA-nı ən son versiyaya yeniləmək və ya təsirlənmiş endpoint-ə girişi məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which version of FUXA is affected by CVE-2026-43947?
This vulnerability affects FUXA SCADA/HMI software version 1.3.0.
Which HTTP request can be used to exploit CVE-2026-43947?
The flaw is exploited via the `POST /api/runscript` endpoint, as it fails to properly validate permissions even when `secureEnabled` is set to `true`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.