Unauthenticated Path Traversal in Golem OEE MES by Neuron
CVE-2026-8464

8.3HIGH

Key Information:

Vendor
CVE Published:
11 June 2026

What is CVE-2026-8464?

The Golem OEE MES software is affected by a vulnerability that enables an unauthenticated path traversal. This issue allows an attacker within the same local network to manipulate HTTP request paths and gain access to arbitrary files on the server's operating system. The vulnerability has been addressed in version 11.6.0 of the software. Ensure that your systems are updated to prevent potential exploitation of this flaw.

Affected Version(s)

Golem OEE MES 0 < 11.6.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol KrĂłlak (securitum.pl)
.