As cited
Copy frozen at (site build).
ot ics
Frangoteam FUXA SCADA/HMI
Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier contain an authentication bypass vulnerability (CVE-2026-13207) that allows unauthenticated attackers to enumerate user accounts and role assignments through dot-segment path normalization in the REST API. The vulnerability exploits improper path normalization before authentication middleware is applied, allowing attackers to access protected endpoints by using sequences like /api/./users or /api/project/../users. Frangoteam recommends upgrading to version 1.3.2 or later to remediate the issue.
Why it matters: Authentication bypass on SCADA/HMI systems in critical infrastructure sectors could enable rapid reconnaissance and lateral movement; patching to 1.3.2 should be prioritized if FUXA is internet-facing.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
Frangoteam FUXA SCADA/HMI
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
Frangoteam FUXA SCADA/HMI
CVE-2026-13207 affects Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier, allowing unauthenticated attackers to enumerate user accounts and role assignments through an authentication bypass vulnerability in the REST application programming interface (API). The vulnerability exploits improper path normalization, where dot-segment sequences such as /api/./users bypass authentication middleware. Frangoteam released version 1.3.2 to remediate the issue.
Why it matters: Organizations deploying FUXA SCADA/HMI in critical manufacturing, energy, water, and wastewater sectors worldwide must upgrade to version 1.3.2 or later immediately, as unauthenticated attackers can discover all user accounts and roles without credentials, creating an immediate exposure for industrial control system (ICS) environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ot ics
Frangoteam FUXA SCADA/HMI
CVE-2026-13207 affects Frangoteam FUXA SCADA/HMI versions 1.3.1 and earlier, allowing unauthenticated attackers to enumerate user accounts and role assignments through an authentication bypass vulnerability in the REST application programming interface (API). The vulnerability exploits improper path normalization, where dot-segment sequences such as /api/./users bypass authentication middleware. Frangoteam released version 1.3.2 to remediate the issue.
Why it matters: Organizations deploying FUXA SCADA/HMI in critical manufacturing, energy, water, and wastewater sectors worldwide must upgrade to version 1.3.2 or later immediately, as unauthenticated attackers can discover all user accounts and roles without credentials, creating an immediate exposure for industrial control system (ICS) environments.
- Source published
- First seen by Cybersecurity Tracker