CVE-2026-94293

Murrelektronik Software AAS Edge Client all versions

Published 6 Oct 2026 · updated 6 Oct 2026 · Received

9.3 Critical · CVSS 4.0, cert.vde.com

Description

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

References