Status: UPDATED
| Advisory ID: CVE-2026-94293
Key Details
| CVE | CVE-2026-94293 |
| CVSS Score / Version | 9.8 (Critical) / CVSS v3.1 |
| Updated | 2026-10-06 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Murrelektronik Software AAS Edge Client all versions |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
What to Do
Monitor Murrelektronik's web page for any future patch releases.
References