← Back to CVE search

CVE-2026-8464

Golem OEE MES

Description

Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server-s operating system by manipulating HTTP request paths. This issue has been fixed in version 11.6.0

CVSS 8.3EPSS 0.20400000000000001%Risk 0.85
View source
Published
2026-06-11 12:16:32
Affected versions
<11.6.0
Type
Other
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X