CyberICT

CVE-2026-94293

Unspecified · Published October 6, 2026

CVSS v3.1

CRITICAL

Description

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

Affected Products

    CVSS Vector

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H