CVE-2026-25893 | frangoteam FUXA up to 1.2.9 Heartbeat Refresh API improper authorization (GHSA-vwcg-c828-9822)
A vulnerability classified as critical was found in frangoteam FUXA up to 1.2.9. Affected is an unknown function of the component Heartbeat Refresh API. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-25893. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.