PatchSiren cyber security CVE debrief
CVE-2026-65984 frangoteam CVE debrief
An attacker possessing a previously issued privileged refresh cookie or access token can continue minting privileged JWTs after account deletion, disablement, role removal, or demotion in FUXA versions 1.3.2 and earlier. This issue allows for continued unauthorized access and configuration changes. The vulnerability is fixed in version 1.3.3, and defenders should prioritize verifying and updating FUXA installations, reviewing and revoking stale access tokens and refresh cookies, and monitoring for suspicious activity.
- Vendor
- frangoteam
- Product
- FUXA
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for FUXA installations, particularly those with privileged access, should assess exposure and prioritize verification and remediation efforts. This includes reviewing and revoking stale access tokens and refresh cookies, monitoring for suspicious activity, and implementing additional security measures to prevent unauthorized access.
Why it matters
Defenders should prioritize verifying and updating FUXA installations, reviewing and revoking stale access tokens and refresh cookies, and monitoring for suspicious activity due to the risk of continued unauthorized access and configuration changes.
- Continued unauthorized access to user management and configuration changes
- Preservation of stale sessions and unauthorized access to runtime configuration and scripts
- Potential creation of backdoor accounts
- Extended window for lateral movement and exploitation
Technical summary
FUXA, a web-based Process Visualization software, has a vulnerability in versions 1.3.2 and earlier. The POST /api/refresh and POST /api/heartbeat endpoints allow an attacker with a previously issued privileged refresh cookie or access token to continue minting privileged JWTs after account deletion, disablement, role removal, or demotion. This issue can lead to continued unauthorized access and configuration changes, and defenders should prioritize verifying and updating FUXA installations to version 1.3.3, reviewing and revoking any stale or unauthorized access tokens and refresh cookies, and monitoring for suspicious activity related to user management and configuration changes.
Defensive priority
Defenders should prioritize verifying and updating FUXA installations to version 1.3.3, reviewing and revoking any stale or unauthorized access tokens and refresh cookies, and monitoring for suspicious activity related to user management and configuration changes.
Recommended defensive actions
- Verify and update FUXA installations to version 1.3.3
- Review and revoke any stale or unauthorized access tokens and refresh cookies
- Monitor for suspicious activity related to user management and configuration changes
- Perform a thorough review of system logs to identify potential security incidents
- Implement additional security measures, such as multi-factor authentication, to prevent unauthorized access
- Conduct a thorough risk assessment to identify potential vulnerabilities and prioritize remediation efforts
- Develop and implement a plan to regularly review and update security configurations and controls
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. GitHub references provide additional context on the fix and vulnerability disclosure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-65984 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-65984
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-65984 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65984
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/frangoteam/FUXA/commit/4fa47d0a2a856ed34f427f472fb4450f86e7749b
-
Source reference
Unverified legacy reference
URL: https://github.com/frangoteam/FUXA/pull/2379
-
Source reference
Unverified legacy reference
URL: https://github.com/frangoteam/FUXA/releases/tag/v1.3.3
-
Source reference
Unverified legacy reference
URL: https://github.com/frangoteam/FUXA/security/advisories/GHSA-rg7m-xwqc-mjw6
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.