CVE-2026-94293 is a critical Missing Authentication for Critical Function (CWE-306) vulnerability affecting the Murrelektronik Software AAS Edge Client, an open-source Asset Administration Shell (AAS) reference client originally built as a trade-fair demonstrator. The client's REST API binds to all network interfaces on TCP port 18000, performs no authentication, and accepts cross-origin requests from any origin, allowing any unauthenticated network attacker to read and modify AAS submodel data. The vulnerability affects all released versions of the product and carries a CVSS v3.1 base score of 9.8 (Critical).
