Critical Unauthorized Access in Asset Administration Shell via CVE-2026-94293
An unauthenticated remote attacker can exploit CVE-2026-94293 to perform unauthorized modifications to submodel data and exfiltrate sensitive information via the Asset Administration Shell.
CVE search metadata
CVE search record: CVE-2026-94293. Severity: critical. CVSS: 9.8. KEV: no. Product: Asset Administration Shell. Brief: Critical Unauthorized Access in Asset Administration Shell via CVE-2026-94293. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-94293/
CVE-2026-94293 represents a critical security flaw in the Asset Administration Shell (AAS) interface, carrying a CVSS v3.1 base score of 9.8. This vulnerability allows an unauthenticated remote attacker to interact with the AAS API without sufficient authorization checks. Specifically, attackers can issue malicious PATCH requests to modify submodel data, potentially leading to system misconfiguration, integrity compromise, or the injection of fraudulent asset data. Furthermore, the vulnerability permits unauthorized GET requests to retrieve all data exposed via the interface, leading to the exfiltration of sensitive asset information. Because the vulnerability does not require authentication, it is highly accessible to any network-adjacent attacker capable of reaching the management API endpoints.
Attack Chain
- Attacker performs reconnaissance to identify internet-facing or internal network-accessible Asset Administration Shell endpoints.
- Attacker interacts with the discovery or root API endpoint to map available submodel resources.
- Attacker sends unauthenticated GET requests to target endpoints to enumerate sensitive system data and submodel configurations.
- Attacker identifies a target submodel resource for modification.
- Attacker constructs and sends a crafted PATCH request to the identified submodel URI.
- The AAS application processes the unauthenticated PATCH request, applying unauthorized changes to the submodel data.
- Attacker repeats the process to achieve broader control or to maintain persistence through malicious configuration changes.
Impact
Successful exploitation allows for the full compromise of data integrity within the Asset Administration Shell, exposing sensitive operational data and allowing unauthorized modification of asset management parameters. This can result in the loss of data confidentiality, the corruption of asset records, and the disruption of industrial or manufacturing processes managed by the AAS.
Recommendation
Prioritize the identification and patching of all instances of Asset Administration Shell within the environment. Ensure that access to the AAS API is restricted via network-level controls such as firewalls or internal network segmentation to block unauthenticated access from unauthorized segments. Monitor web server logs for anomalous patterns of PATCH requests or high volumes of GET requests targeting the AAS API endpoints.
Rules
title: "Detects CVE-2026-94293 Exploitation - Unauthorized PATCH or GET Requests to AAS API" description: "Detects unauthorized access attempts to the Asset Administration Shell API via PATCH or GET requests from unauthenticated or suspicious sources." logsource: category: "webserver" detection: selection: cs-uri-stem|contains: "/submodel" cs-method|in:
- "GET"
- "PATCH" filter: sc-status|startswith: "4" condition: selection and not filter level: "critical" tags:
- "attack.initial_access"
- "attack.exfiltration"
- "attack.t1190" tests: positive:
- name: "Successful PATCH request to submodel endpoint" data:
- cs-method: "PATCH" cs-uri-stem: "/submodel/data/1" sc-status: "200" negative:
- name: "Blocked request to submodel endpoint" data:
- cs-method: "GET" cs-uri-stem: "/submodel/data/1" sc-status: "403" falsepositives:
- "Legitimate administrative tools or authorized API integrations interacting with the AAS API." handoff: detection_confidence: "medium" required_telemetry:
- log_source: "webserver" event_or_channel: "HTTP access logs" required_fields:
- "cs-method"
- "cs-uri-stem"
- "sc-status" availability: "available" notes: "Requires web server access logs with full URI and method visibility." validation: status: "needs_environment_validation" steps:
- "Check baseline traffic volume to AAS endpoints to minimize noise." expected_telemetry: "Web server access logs showing successful 200 or 204 status codes for PATCH/GET requests." pass_criteria: "Detection triggers on requests to AAS submodel endpoints." known_evasions:
- "Traffic obfuscation via encrypted tunnels or proxies." limitations:
- "Does not distinguish between legitimate and malicious authorized users; requires baseline tuning." tuning:
- source: "Monitoring/Management tools" guidance: "Allowlist known internal source IPs of management tools." portability_notes:
- platform: "Splunk|Elastic|Sentinel" note: "Ensure field mapping of standard IIS/Nginx logs to webserver schema." suggested_owner: "Detection Engineering"
Immediate actions
Deploy webserver detection rule and baseline AAS API traffic.
Threat Hunt
Search web logs for PATCH requests targeting /submodel endpoints.
Data: webserver logs
Mitigations
Restrict network access to AAS management interfaces via firewall rules.
CVE-2026-94293