CVE-2026-65984: CWE-613: Insufficient Session Expiration in frangoteam FUXA
FUXA versions 1.3.2 and earlier suffer from insufficient session expiration, allowing attackers with previously issued privileged refresh cookies or access tokens to continue minting privileged JWTs even after account deletion or role changes. This enables unauthorized persistent access to sensitive functions such as user management and backdoor account creation. The vulnerability is fixed in version 1.3.3.
AI Analysis
Technical Summary
FUXA, a web-based SCADA/HMI/Dashboard software, has an insufficient session expiration vulnerability (CWE-613) in versions 1.3.2 and earlier. The POST /api/refresh endpoint falls back to decoded.groups even when the user is deleted or groups are zero, and the POST /api/heartbeat endpoint re-signs inbound JWT claims without validating the current database record. This allows an attacker possessing a previously issued privileged refresh cookie or access token to mint privileged JWTs continuously after account deletion, disablement, or role changes, effectively extending stale sessions and preserving unauthorized access to critical functionalities. The issue is resolved in version 1.3.3.
Potential Impact
An attacker with a previously issued privileged refresh cookie or access token can maintain unauthorized privileged access by minting new JWTs after the associated user account is deleted, disabled, or demoted. This persistent access can lead to unauthorized user management, project manipulation, runtime configuration changes, script execution, and creation of backdoor accounts, posing a significant security risk.
Mitigation Recommendations
Upgrade FUXA to version 1.3.3 or later, where this vulnerability is fixed. No other mitigation is indicated by the vendor advisory.
CVE-2026-65984: CWE-613: Insufficient Session Expiration in frangoteam FUXA
Description
FUXA versions 1.3.2 and earlier suffer from insufficient session expiration, allowing attackers with previously issued privileged refresh cookies or access tokens to continue minting privileged JWTs even after account deletion or role changes. This enables unauthorized persistent access to sensitive functions such as user management and backdoor account creation. The vulnerability is fixed in version 1.3.3.
CVSS v4.0
Score 7.5high
Affected software
frangoteam
FUXA
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FUXA, a web-based SCADA/HMI/Dashboard software, has an insufficient session expiration vulnerability (CWE-613) in versions 1.3.2 and earlier. The POST /api/refresh endpoint falls back to decoded.groups even when the user is deleted or groups are zero, and the POST /api/heartbeat endpoint re-signs inbound JWT claims without validating the current database record. This allows an attacker possessing a previously issued privileged refresh cookie or access token to mint privileged JWTs continuously after account deletion, disablement, or role changes, effectively extending stale sessions and preserving unauthorized access to critical functionalities. The issue is resolved in version 1.3.3.
Potential Impact
An attacker with a previously issued privileged refresh cookie or access token can maintain unauthorized privileged access by minting new JWTs after the associated user account is deleted, disabled, or demoted. This persistent access can lead to unauthorized user management, project manipulation, runtime configuration changes, script execution, and creation of backdoor accounts, posing a significant security risk.
Mitigation Recommendations
Upgrade FUXA to version 1.3.3 or later, where this vulnerability is fixed. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-23T18:54:15.832Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a84be80c6e8be0332b43d21
Added to database: 08/18/2026, 20:20:16 UTC
Last enriched: 09/11/2026, 20:49:21 UTC
Last updated: 10/02/2026, 02:46:05 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.