CVE-2026-94293
Unspecified · Published October 6, 2026
9.8
CVSS v3.1
CRITICALDescription
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
Affected Products
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H