Junglewise Threat Intelligence

CVE-2026-8464: Neuron Soft Golem OEE MES path traversal in mobile server

CVE-2026-8464 · Severity: info · CVSS 8.3 · Published 2026-06-11

Executive brief

Golem OEE MES, a manufacturing execution system used to monitor production efficiency, contains a security flaw that allows unauthorized users on the same local network to access sensitive files. By sending specially crafted web requests, an attacker can bypass security restrictions to read arbitrary files from the server's operating system. This could lead to the exposure of configuration data, system credentials, or other sensitive business information.

Technical details

A path traversal vulnerability (CWE-22) exists in the mobile application server component of Golem OEE MES. The flaw stems from insufficient validation of HTTP request paths, allowing unauthenticated attackers located within the same local network (Adjacent) to use directory traversal sequences (e.g., ../) to access files outside of the intended web root. An attacker can exploit this to read sensitive operating system files or application configuration data. The issue is resolved in version 11.6.0.

Affected products

  • Neuron Soft Golem OEE MES All versions before 11.6.0

Timeline

  • 2026-05-05: patched: Version 11.6.0 released to address the vulnerability.
  • 2026-06-11: disclosed: Public disclosure by CERT.PL.
  • 2026-06-11: advisory

References