CVE-2026-58115
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedA vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges. Source description excerpt; complete tracked detail loads below.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-11 12:20 UTC · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
What is affected
ReportedSiemens — SIMATIC IoT2050 Advanced. Product-level identification only; no affected-version conclusion is available from this field.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-11 12:20 UTC · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
Urgency and basis
ReportedTrack* · 221.3
Evidence: Tracker computed · Tracker decision tier from the evidence detailed below · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
Exploitation evidence
Not reportedNot reported by tracked sources.
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…