OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-94293

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit this vulnerability to modify Asset Administration Shell submodel data through malicious PATCH requests, while also gaining access to all data exposed by the GET endpoints. The critical severity of this issue (CVSS 9.8) necessitates immediate attention from organizations utilizing affected products, particularly those managing sensitive asset data. Security teams should prioritize patching and implementing access controls to mitigate potential data breaches and unauthorized modifications.

CVE
CVE-2026-94293
Severity
CRITICAL
CVSS
9.8
EPSS
N/A

Original NVD Description

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.