AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-58115

CRITICAL · CVSS 10 EPSS 0.65%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability affects SIMATIC IoT2050 Advanced devices running versions prior to V4.3.4.1 with Node-RED installed, which lack authentication enforcement on the Node-RED HTTP interface. This flaw enables unauthenticated remote attackers to access programming nodes, potentially allowing them to execute arbitrary code with maximum privileges on the server. Organizations utilizing these devices should prioritize immediate remediation to mitigate the risk of unauthorized access and system compromise.

CVE
CVE-2026-58115
Severity
CRITICAL
CVSS
10
EPSS
0.65%

Original NVD Description

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.