CVE-2026-94293 is a critical missing-authentication flaw (CVSS 3.1: 9.8) in Murrelektronik's Software AAS Edge Client: a remote attacker with no credentials can read exposed data and change Asset Administration Shell submodel data.
What Is It
The NVD description says an unauthenticated remote attacker can change Asset Administration Shell (AAS) submodel data with PATCH requests. The same attacker can read all data that the client's GET endpoints expose.
The weakness is classified as CWE-306 (Missing Authentication for Critical Function). CERT@VDE ([email protected]) reported it, and NVD published it on 2026-10-06. The NVD record's status is still "Received."
Why It Matters
The CVSS scores show how easy this is to exploit:
- CVSS 3.1: 9.8 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). This is the primary score. - CVSS 4.0: 9.3 CRITICAL. This is the secondary score.
An attacker can reach the client over the network. The attack is low in complexity and needs no privileges or user interaction. The impact on confidentiality, integrity and availability is rated High in both scores.
In practice, anyone who can reach the affected service can read its exposed AAS data and change submodel data.
Exploitation status: The supplied CISA KEV entry is empty, so CISA has not confirmed active exploitation in the source material. The CVSS 4.0 exploit maturity field is "Not Defined."
What's Vulnerable
| Vendor | Product | Affected versions |
|---|---|---|
| Murrelektronik | Software AAS Edge Client | All versions |
The NVD record lists no CPE entries.
Patch Status
The supplied NVD data has no fixed version or patch information. Because there is no KEV entry, there is also no CISA-mandated required action or due date.
Defenders should read CERT@VDE advisory VDE-2026-108 (linked below) for vendor remediation guidance. Until fixes are confirmed, treat every deployed instance of the Software AAS Edge Client as affected.
Sources
- NVD: CVE-2026-94293
- CERT@VDE Advisory VDE-2026-108
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE in the supplied data)