What is CVE-2026-47721?
CVE-2026-47721 is an authorization bypass vulnerability in FUXA SCADA software before version 1.3.2. An authenticated non-admin operator can create or delete scheduler settings via the `/api/scheduler` endpoints without proper admin permission checks. Upgrading to version 1.3.2 or later mitigates the issue.
Azərbaycanca: CVE-2026-47721 FUXA SCADA proqramında autentifikasiya zəifliyidir. 1.3.2 versiyasından əvvəl, autentifikasiya olunmuş qeyri-admin operator `/api/scheduler` endpoint-ləri vasitəsilə icazəsiz scheduler parametrlərini yarada və ya silə bilər. Təhlükəsizlik üçün proqramı dərhal 1.3.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Through which endpoint is CVE-2026-47721 exploited?
The vulnerability is exploited through the `/api/scheduler` endpoints.
To which version should FUXA SCADA be upgraded to mitigate CVE-2026-47721?
It is recommended to upgrade to version 1.3.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.