CVE-2026-94293

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets2 URLs
Full discourse2 posts
  • ThreatAft@ThreatAft

    🚨 AAS EDGE CLIENT — CVE-2026-94293, CVSS 9.8 Unauth read/write on industrial submodel data via REST API on port 18000. All versions affected. NO PATCH WILL SHIP. DECOMMISSION NOW 🔗 https://threataft.com/articles/aas-edge-client-cve-2026-94293?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #IIoT #OTSecurity #CVE #ICS

    000002
    46 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now. #Murrelektronik #AAS #CVE202694293 #ICS #OTSecurity #Industry40 #MissingAuthentication #Vulnerability https://securityonline.info/aas-edge-client-vulnerability-cve-2026-94293/

    00000186
    13.0K followersView on X

Explore more