Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by manipulating HTTP request paths.
This issue has been fixed in versionĀ 11.6.0
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by manipulating HTTP request paths. This issue has been fixed in versionĀ 11.6.0 | |
| Title | Path traversal in Neuron Soft Golem OEE MES | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-06-11T12:13:26.247Z
Reserved: 2026-05-13T11:32:03.878Z
Link: CVE-2026-8464
Updated: 2026-06-11T12:13:11.475Z
Status : Received
Published: 2026-06-11T12:16:32.717
Modified: 2026-06-11T12:16:32.717
Link: CVE-2026-8464
No data.
OpenCVE Enrichment
Updated: 2026-06-11T12:30:14Z