CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-58115 — A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac

Analysis

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. CVSS Score: 10. Published: 2026-08-11T13:19:00.190.

Indicators of Compromise (1)

CVE (1)
CVE-2026-58115
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats