External risk intelligence

Asset Administration Shell Data Exposure and Modification Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-94293

The vulnerability affects Asset Administration Shell endpoints, which frequently function as web or API interfaces for industrial and asset management systems. Because these interfaces are often deployed to facilitate data exchange across network boundaries or through API gateways, they are commonly exposed as internet-facing services.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability allows unauthenticated remote attackers to read or modify sensitive data within Asset Administration Shell submodels, potentially impacting the integrity and confidentiality of asset information. It affects technologies that utilize Asset Administration Shell endpoints, which can be exposed externally.

  • Unauthenticated attackers can access or alter asset data.
  • Executive attention is needed to confirm relevance and exposure.
  • Understand potential data integrity and confidentiality risks.

Attack Path

How an attacker could exploit the issue

An attacker can remotely access and modify data within the Asset Administration Shell submodel without needing authentication. This can be achieved by sending specially crafted PATCH requests to alter data, or GET requests to read any exposed information.

  • No authentication is required.
  • Attacker sends PATCH or GET requests.
  • Risk of unauthorized data modification or exposure.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could modify critical Asset Administration Shell submodel data and read all exposed data. This could occur when the system is configured to allow unauthenticated PATCH or GET requests to these endpoints.

  • Asset Administration Shell submodel data.
  • Via unauthenticated network requests.
  • Unauthorized data access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Asset Administration Shell submodel data, allowing unauthenticated remote attackers to modify and read data via PATCH and GET requests, impacts systems that expose these endpoints. Technical leaders and security teams should first identify all instances of the affected technology, determine their exposure and business criticality, and then locate the accountable owner to prioritize remediation efforts.

  • Asset Administration Shell owners are responsible.
  • Verify external reachability and business impact first.
  • Plan remediation based on confirmed risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is an Asset Administration Shell?

It is a standardized digital representation of an industrial asset, such as a machine or component. It acts as an interface for exchanging technical data, status information, and life-cycle records between systems. By providing a common format, it allows different software applications in manufacturing and engineering environments to communicate about physical hardware effectively.

What does CWE-306 mean for CVE-2026-94293?

CWE-306 refers to 'Missing Authentication for Critical Function.' In this case, it means the software performs sensitive operations—specifically reading or changing data within the submodel—without verifying who is making the request. Because the system lacks this gatekeeper, any remote actor can interact with these critical functions as if they were authorized users.

How do attackers trigger this vulnerability?

An attacker triggers the flaw by sending standard network requests to the Asset Administration Shell. Specifically, they use GET requests to read data or PATCH requests to modify it. This does not require any prior access, credentials, or complex exploits; simply reaching the endpoint over the network is sufficient to bypass the intended security controls.

Is my system at risk if it is not internet-facing?

Halo Surface Signal indicates that Asset Administration Shells are often placed on internet-facing gateways to facilitate broad data exchange. While systems confined to strictly internal, isolated networks are less reachable by external attackers, they remain potentially vulnerable to anyone—including malicious insiders—who has network connectivity to those specific service endpoints.

Do I need to take action if I use this technology?

Yes. First, perform an inventory to locate all deployed Asset Administration Shells. Assess whether these instances are reachable from untrusted networks and evaluate the sensitivity of the data they handle. Once you identify the asset owners, prioritize these systems for remediation to ensure that proper authentication mechanisms are implemented and enforced.

References