CVE-2026-13207Disclosure

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticated requests to access protected endpoints by prefixing paths with dot-segments such as /api/./users, /api/./roles, and /api/project/../users. These requests bypass authentication checks and return sensitive user and role data without credentials.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-01: 2Active Exploitation · 2026-07-01: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 206-3007-01
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-012
Active Exploitation1Disclosure1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-13207 to bypass FUXA SCADA authentication via path normalization, then escalating privileges and moving laterally through industrial networks. Runtime segmentation helps contain post-compromise activity in critical infrastructure environments. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/frangoteam-fuxa-scada-hmi-authentication-bypass-cve-2026-13207

    Post summary

    The analysis confirms that CVE-2026-13207 is actively exploited to bypass SCADA authentication and laterally move within industrial networks, with detailed technical tactics disclosed but no patch or mitigation mentioned.

    0000059
    1.9K followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [Threat Brief] Frangoteam FUXA SCADA/HMI Account Enumeration (CVE-2026-13207): Unauthenticated Recon on Open-Source HMI Deployments https://breachspider.com/intel/2026-07-01-frangoteam-fuxa-scada-hmi-account-enumeration-cve-2026-13207 #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The brief announces CVE-2026-13207 as an unauthenticated account enumeration flaw in open‑source HMI deployments, but does not provide PoC, exploit code, or patch information.

    0000062
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13207 FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot… https://www.cve.org/CVERecord?id=CVE-2026-13207 ----- Traducción: CVE-2026-13207 FUX… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑13207, an authentication bypass flaw in FUXA caused by improper dot‑segment path normalization in the REST API.

    0000039
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13207 FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot… https://www.cve.org/CVERecord?id=CVE-2026-13207

    Post summary

    The entry reveals CVE‑2026‑13207 as an authentication bypass in FUXA’s REST API caused by improper dot‑segment path normalization, but offers no PoC, exploit code, or patch information.

    00000583
    57.7K followersView on X

Explore more