
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25938 is an authentication bypass vulnerability in FUXA, a web-based Process Visualization (SCADA/HMI/Dashboard) software, that allows unauthenticated remote attackers to execute arbitrary code on the server when the Node-RED plugin is enabled. It affects FUXA versions 1.2.8 through 1.2.10 (npm package fuxa-server), and was disclosed on February 9, 2026, with a patch released the same day in version 1.2.11. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.5 (Critical) (GitHub Advisory, FUXA Security Advisory).
The root cause is a combination of missing authentication for a critical function (CWE-306) and authentication bypass by spoofing (CWE-290) in FUXA's Node-RED integration layer. In vulnerable versions, the allowDashboard middleware in server/integrations/node-red/index.js unconditionally permitted requests to the /nodered/flows endpoint — and other Node-RED admin API paths — without verifying any JWT or API key, even when runtime.settings.secureEnabled was set to true. An attacker could send a specially crafted HTTP POST request directly to the /nodered/flows endpoint to submit a malicious Node-RED flow configuration, gaining administrative access to the Node-RED deployment API and achieving arbitrary code execution in the context of the FUXA service process. The fix (commit 5e7679b) introduced proper JWT and API key validation middleware for all Node-RED admin endpoints, and made dangerous modules such as child_process and net opt-in only via a new nodeRedUnsafeModules setting (GitHub Advisory, Patch Commit).
Successful exploitation grants an unauthenticated remote attacker full administrative control over the Node-RED deployment API, enabling arbitrary code execution in the context of the FUXA service account. This results in high impact to confidentiality, integrity, and availability of the affected system, and may lead to complete server compromise. Because FUXA is commonly deployed in ICS/SCADA environments, exploitation could further expose connected industrial control systems to follow-on actions such as manipulation of physical processes, lateral movement within OT networks, or data exfiltration of sensitive operational data (FUXA Security Advisory, GitHub Advisory).
As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation (Feedly). However, a Nuclei detection template pull request was submitted to the ProjectDiscovery repository, indicating active community interest in automated scanning for this vulnerability. The EPSS score is approximately 0.097% (35th percentile), reflecting a currently low but non-negligible exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Qualys has assigned detection ID 5007591 for this CVE (Feedly).
/nodered/ or /nodered/flows./nodered/flows on the target. In vulnerable versions, the server returns the current flow configuration without requiring authentication, confirming exploitability.exec node or equivalent that executes an arbitrary OS command (e.g., a reverse shell command). Node-RED's exec node passes input directly to the system shell./nodered/flows with the malicious flow JSON as the request body and Content-Type: application/json. No authentication token or credentials are required in vulnerable versions./nodered/flows, /nodered/flows/state, or /nodered/flows/deploy from external or unexpected IP addresses; outbound connections from the FUXA server process to unknown external hosts (potential reverse shell callbacks)./nodered/flows or other /nodered/ admin endpoints without a valid x-access-token, x-api-key header, or nodered_auth cookie; HTTP 200 responses to unauthenticated POST requests on these endpoints in versions prior to 1.2.11.flows.json file in the FUXA Node-RED user directory containing unexpected exec, function, or HTTP request nodes with suspicious command strings; unexpected scripts or binaries written to the FUXA installation directory./bin/sh, bash, cmd.exe, curl, wget, python, nc) that are not part of normal FUXA operation; unexpected network listeners created by child processes of the FUXA service.The primary remediation is to upgrade FUXA to version 1.2.11 or later, which introduces proper JWT and API key authentication enforcement on all Node-RED admin endpoints (FUXA Release v1.2.11, Patch Commit). If an immediate upgrade is not possible, disable the Node-RED plugin in FUXA settings if it is not operationally required. Additionally, restrict network access to the FUXA server (default port 1881) using firewall rules and network segmentation, limiting exposure to trusted hosts and networks only, particularly in ICS/SCADA environments (Feedly).
The vulnerability was reported by researcher wodzen and published by the FUXA maintainer unocelli on February 9, 2026, with a same-day patch release. A technical deep-dive and PoC/mitigation walkthrough was published by Undercode Testing, and a dev.to post titled "CVE-2026-25938: FUXA RCE — When the Dashboard Becomes a Command Prompt" highlighted the risk to ICS/SCADA operators. A Nuclei detection template was submitted to ProjectDiscovery's community repository, reflecting active interest from the security research community in automated detection. Red Hat and INCIBE-CERT also tracked the vulnerability in their advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."