{"id":"GHSA-8ghr-w65f-j3qr","summary":"FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions","details":"## Summary\n\nAn authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions that should be restricted to administrators.\n\n## Details\n\nThe Scheduler API did not correctly enforce administrator permissions when processing scheduler modifications.\n\nAs a result, authenticated users with non-administrative roles could create or modify scheduled actions that execute privileged operations, including device value changes and server-side script execution.\n\nThe issue was fixed in version 1.3.2 by enforcing the appropriate permission checks for scheduler modifications.\n\n\n## Impact\n\nAn operator-level user in FUXA reaches the PLC-write and server-side-script-execution surface that the platform otherwise restricts to administrators. In a SCADA deployment those two privileges cover setpoint control and the automation scripting engine. Alice schedules a job that rewrites a pump's enable tag, opens a safety interlock, or runs a project script that walks the device tree. The scheduled-action model extends the attack: Alice does not need to keep a session open for the action to fire, and a repeating schedule re-applies her changes every cycle even if an admin reverts them manually.\n\n**CVSS 3.1**: `AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L` (Medium, 6.3). CWE-862.\n\n## Recommended Fix\n\nAdd `authJwt.haveAdminPermission(permission)` to both `POST /api/scheduler` and `DELETE /api/scheduler`, matching every other write endpoint that reaches `runtime.devices.setTagValue` or `runtime.scriptsMgr.runScript`.\n\n```javascript\nschedulerApp.post(\"/api/scheduler\", secureFnc, function(req, res) {\n    if (res.statusCode === 403) {\n        runtime.logger.error(\"api post scheduler: Tocken Expired\");\n        return;\n    }\n    const permission = checkGroupsFnc(req);\n    const isGuest = authJwt.isGuestUser(req.userId, req.userGroups);\n    if (runtime.settings?.secureEnabled && (isGuest || !authJwt.haveAdminPermission(permission))) {\n        res.status(401).json({error:\"unauthorized_error\", message: \"Unauthorized!\"});\n        runtime.logger.error(\"api post scheduler: admin permission required\");\n        return;\n    }\n    // ... rest unchanged ...\n});\n```\n\nApply the same change to the delete handler at `server/api/scheduler/index.js:102-112`. As defense in depth, the scheduler service should also validate each `deviceActions` entry against the creator's stored groups before execution (e.g., reject `onRunScript` on any scheduler whose author is not an admin at execution time).\n\n---\nA fix is available at https://github.com/frangoteam/FUXA/releases/tag/v1.3.2.\n\n---\n*Found by [aisafe.io](https://aisafe.io)*","aliases":["CVE-2026-47721"],"modified":"2026-06-08T23:26:35.850398Z","published":"2026-06-08T23:07:02Z","database_specific":{"github_reviewed_at":"2026-06-08T23:07:02Z","nvd_published_at":null,"cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/frangoteam/FUXA/security/advisories/GHSA-8ghr-w65f-j3qr"},{"type":"PACKAGE","url":"https://github.com/frangoteam/FUXA"},{"type":"WEB","url":"https://github.com/frangoteam/FUXA/releases/tag/v1.3.2"}],"affected":[{"package":{"name":"fuxa-server","ecosystem":"npm","purl":"pkg:npm/fuxa-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.14-1243"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-8ghr-w65f-j3qr/GHSA-8ghr-w65f-j3qr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}