Remote Code Modification Vulnerability in Asset Administration Shell by Vendor
CVE-2026-94293
9.3CRITICAL
What is CVE-2026-94293?
A security flaw exists in the Asset Administration Shell that allows unauthenticated remote attackers to send PATCH requests, enabling them to modify submodel data. Additionally, attackers can exploit this vulnerability to access all data returned by the GET endpoints, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
Software AAS Edge Client all 0.0.0
