CVE-2026-47721: FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
An authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions that should be restricted to administrators.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-47721 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →