CVE-2026-94293 - Missing authentication for critical function in the aas-edge-client REST API
CVE ID :CVE-2026-94293
Published : Oct. 6, 2026, 7:17 a.m. | 28 minutes ago
Description :An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 6, 2026, 7:17 a.m. | 28 minutes ago
Description :An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...