CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Frangoteam FUXA SCADA/HMI

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 268

As cited

Copy frozen at (site build).

ot ics

Frangoteam FUXA SCADA/HMI

Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier contain an authentication bypass vulnerability (CVE-2026-13207) that allows unauthenticated attackers to enumerate user accounts and role assignments through dot-segment path normalization in the REST API. The vulnerability exploits improper path normalization before authentication middleware is applied, allowing attackers to access protected endpoints by using sequences like /api/./users or /api/project/../users. Frangoteam recommends upgrading to version 1.3.2 or later to remediate the issue.

Why it matters: Authentication bypass on SCADA/HMI systems in critical infrastructure sectors could enable rapid reconnaissance and lateral movement; patching to 1.3.2 should be prioritized if FUXA is internet-facing.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ot ics

Frangoteam FUXA SCADA/HMI

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ot ics

Frangoteam FUXA SCADA/HMI

CVE-2026-13207 affects Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier, allowing unauthenticated attackers to enumerate user accounts and role assignments through an authentication bypass vulnerability in the REST application programming interface (API). The vulnerability exploits improper path normalization, where dot-segment sequences such as /api/./users bypass authentication middleware. Frangoteam released version 1.3.2 to remediate the issue.

Why it matters: Organizations deploying FUXA SCADA/HMI in critical manufacturing, energy, water, and wastewater sectors worldwide must upgrade to version 1.3.2 or later immediately, as unauthenticated attackers can discover all user accounts and roles without credentials, creating an immediate exposure for industrial control system (ICS) environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ot ics

Frangoteam FUXA SCADA/HMI

CVE-2026-13207 affects Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier, allowing unauthenticated attackers to enumerate user accounts and role assignments through an authentication bypass vulnerability in the REST application programming interface (API). The vulnerability exploits improper path normalization, where dot-segment sequences such as /api/./users bypass authentication middleware. Frangoteam released version 1.3.2 to remediate the issue.

Why it matters: Organizations deploying FUXA SCADA/HMI in critical manufacturing, energy, water, and wastewater sectors worldwide must upgrade to version 1.3.2 or later immediately, as unauthenticated attackers can discover all user accounts and roles without credentials, creating an immediate exposure for industrial control system (ICS) environments.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary