CVE-2026-25939: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-25939 is an authorization bypass vulnerability in FUXA, a web-based Process Visualization (SCADA/HMI/Dashboard) software, that allows unauthenticated remote attackers to create, modify, or delete arbitrary schedulers. It affects FUXA versions 1.2.8 through 1.2.10 (npm package fuxa-server) and was disclosed on February 9, 2026, with a patch released the same day in version 1.2.11. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, FUXA Security Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the FUXA API endpoints for scheduler creation (POST /api/scheduler) and deletion (DELETE /api/scheduler) did not enforce authorization checks against guest-level tokens, even when runtime.settings.secureEnabled was set to true. An unauthenticated attacker can exploit the /api/heartbeat endpoint to automatically obtain a guest JWT token, then use that token to invoke scheduler mutation endpoints without restriction. The fix, introduced in commit 5782b35, adds an isGuestUser() check in server/api/scheduler/index.js that returns HTTP 401 for guest users when secure mode is enabled (GitHub Commit, FUXA Security Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to create, modify, or delete FUXA schedulers, which can be configured to trigger immediately or on a recurring cycle. This enables an attacker to force connected ICS/SCADA devices to specific states or values, or execute existing server-side scripts, potentially causing operational disruption, equipment damage, or safety incidents in industrial environments. The vulnerability has high integrity and availability impact on both the vulnerable system and any subsequently connected systems, though there is no direct confidentiality impact (GitHub Advisory, FUXA Security Advisory).

Exploitability

A public proof-of-concept exploit is available on GitHub at mbanyamer/CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary, published approximately March 2, 2026. A Nuclei detection template has also been submitted to the projectdiscovery/nuclei-templates repository. As of the latest available data, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.022% (6th percentile), and the vulnerability is not currently listed in the CISA KEV catalog (Feedly, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible FUXA instances running versions 1.2.8–1.2.10 using tools like Shodan (search for fuxa or the default FUXA web port) or by scanning for the FUXA web interface.
  2. Obtain guest token: Send a POST request to /api/heartbeat on the target FUXA instance. Even without credentials, the server automatically issues a guest JWT token in the response when secureEnabled is true.
  3. Craft scheduler payload: Prepare a JSON payload for scheduler creation, specifying a scheduler ID, trigger timing (immediate or cyclic), target device states/values, or an existing server-side script to execute.
  4. Send unauthorized scheduler mutation: Submit a POST request to /api/scheduler with the guest JWT token in the Authorization header and the crafted payload. Due to the missing authorization check, the server processes the request and creates or modifies the scheduler.
  5. Trigger follow-on actions: The newly created scheduler executes at the configured time, forcing connected ICS/SCADA devices to attacker-specified states or running server scripts, achieving operational disruption or further compromise (FUXA Security Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unexpected POST or DELETE requests to /api/scheduler from unauthenticated or guest-level sources; repeated POST requests to /api/heartbeat from external or unknown IP addresses without subsequent authenticated activity.
  • Logs: FUXA server logs showing guest JWT token issuance followed immediately by scheduler API calls; log entries such as api post scheduler: Unauthorized guest (present only after patching) or absence of such entries in unpatched versions despite scheduler changes; Morgan access log entries for /api/scheduler with guest-associated tokens.
  • Application State: Unexpected, newly created, or modified schedulers in the FUXA scheduler configuration, especially those set to trigger immediately or cyclically; schedulers referencing unusual device states or server-side scripts not created by authorized users (FUXA Security Advisory, GitHub Commit).

Mitigation and workarounds

Upgrade FUXA to version 1.2.11 or later immediately, as this release blocks guest access to scheduler mutation endpoints (POST /api/scheduler and DELETE /api/scheduler) (FUXA Release). Until patching is complete, implement network-level access controls (firewall rules, VPN, or network segmentation) to restrict access to FUXA instances to only authorized personnel and systems. Monitor FUXA logs for unexpected scheduler creation or modification activity as a compensating control.

Community reactions

The vulnerability was reported by security researcher 'wodzen' and published by the FUXA maintainer 'unocelli' on February 9, 2026 (FUXA Security Advisory). A technical write-up was published at infinitsec.net shortly after disclosure, and Check Point Research included the vulnerability in their advisory catalog (CPAI-2026-1537). The availability of a public PoC and a Nuclei detection template has drawn attention from the security community given the ICS/SCADA context of the affected software.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management