chiprook
← Security
SecurityOctober 6, 2026, 18:30

CVE-2026-94293: AAS Edge Client flaw rated 9.8, no patch

Murrelektronik's AAS Edge Client contains CVE-2026-94293 (CVSS 9.8): an unauthenticated REST API on TCP port 18000 bound to all interfaces. Any network-reachable attacker can read AAS submodel data via GET and overwrite it via PATCH, with changes propagating to central AAS servers. No patch exists; the vendor archived the repositories and recommends decommissioning.

CVE-2026-94293: AAS Edge Client flaw rated 9.8, no patch
#Murrelektronik
Read next
Security

IBM patches 12 flaws in MQ and Langflow OSS, three rated 9.8

Security

Mooncake flaws rated up to 9.8 allow unauthenticated memory read/write

Security

Gitea 1.27.1 fixes CVE-2026-60004 rated 9.8

Security

CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8