What is CVE-2026-47718?
In FUXA SCADA software version 1.3.0-2773, even with `secureEnabled=true`, guest users and requests with invalid tokens can still read project, alarms, and scheduler APIs. This issue is fixed in version 1.3.1.
Azərbaycanca: FUXA SCADA proqramında `secureEnabled=true` parametri aktiv olsa belə, 1.3.0-2773 versiyasında `guest` istifadəçilər və etibarsız tokenlə daşıyan sorğular layihə, həyəcan siqnalları və planlayıcı API-larına giriş əldə edə bilir. Bu boşluq 1.3.1 versiyasında aradan qaldırılıb.
Related CVEs
link basis: same weakness class CWE-306
FAQ1
In FUXA SCADA version 1.3.0-2773, which users can still access project, alarms, and scheduler APIs even with `secureEnabled=true`?
Guest users and requests with invalid tokens can still read these APIs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.