# CVE-2026-47717: FUXA - Information Disclosure

> Live exploitation tracking for CVE-2026-47717 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-47717

## Key facts

- **Exploitation phase:** Active Exploitation. The vulnerability is actively exploited at scale across the internet, often via automated tools and large attack campaigns.
- **Public exploit available:** Yes
- **Affected products:** Frangoteam FUXA
- **Weaknesses:** CWE-201 (Insertion of Sensitive Information Into Sent Data)
- **Tags:** enterprise_software

## Description

The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled.

## CrowdSec analysis

[CVE-2026-47717](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-47717) is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-47717 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2026-47717 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2026-47717 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers exploit unauthenticated access to the `/api/project` endpoint on FUXA servers, allowing them to retrieve sensitive ICS/SCADA project configuration data without credentials.

## Timeline

- 2026-05-27: CVE Published. CVE-2026-47717 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-47717 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-47717 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-47717.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-47717) follows observed exploitation activity for CVE-2026-47717. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
