FUXA - Information Disclosure (CVE-2026-47717)
Description
The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled.
psychologyCrowdSec Analysis
CVE-2026-47717 is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
CrowdSec network data shows that most actors exploiting CVE-2026-47717 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2026-47717 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2026-47717 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.
Attackers exploit unauthenticated access to the /api/project endpoint on FUXA servers, allowing them to retrieve sensitive ICS/SCADA project configuration data without credentials.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-05-27 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-06-25 |