Cyber & AI intelligence
Wasteland.
Briefs indexed3027
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94293 2026-10-06

Murrelektronik AAS Edge Client Lets Unauthenticated Attackers Read and Modify Asset Data (CVE-2026-94293)

"CVE-2026-94293 is a critical missing-authentication flaw (CVSS 3.1: 9.8) in Murrelektronik's Software AAS Edge Client: a remote attacker with no credentials can read exposed data and change Asset Administration Shell…"

CVE-2026-94293 is a critical missing-authentication flaw (CVSS 3.1: 9.8) in Murrelektronik's Software AAS Edge Client: a remote attacker with no credentials can read exposed data and change Asset Administration Shell submodel data.

What Is It

The NVD description says an unauthenticated remote attacker can change Asset Administration Shell (AAS) submodel data with PATCH requests. The same attacker can read all data that the client's GET endpoints expose.

The weakness is classified as CWE-306 (Missing Authentication for Critical Function). CERT@VDE ([email protected]) reported it, and NVD published it on 2026-10-06. The NVD record's status is still "Received."

Why It Matters

The CVSS scores show how easy this is to exploit:

An attacker can reach the client over the network. The attack is low in complexity and needs no privileges or user interaction. The impact on confidentiality, integrity and availability is rated High in both scores.

In practice, anyone who can reach the affected service can read its exposed AAS data and change submodel data.

Exploitation status: The supplied CISA KEV entry is empty, so CISA has not confirmed active exploitation in the source material. The CVSS 4.0 exploit maturity field is "Not Defined."

What's Vulnerable

Vendor Product Affected versions
Murrelektronik Software AAS Edge Client All versions

The NVD record lists no CPE entries.

Patch Status

The supplied NVD data has no fixed version or patch information. Because there is no KEV entry, there is also no CISA-mandated required action or due date.

Defenders should read CERT@VDE advisory VDE-2026-108 (linked below) for vendor remediation guidance. Until fixes are confirmed, treat every deployed instance of the Software AAS Edge Client as affected.

Sources