Article

    Cyber News / Article / Vulnerability in Golem OEE MES software

    Vulnerability in Golem OEE MES software
    CE
    CERT Polska-2026-06-11

    Vulnerability in Golem OEE MES software

    CERT Polska has received a report about vulnerability in Neuron Soft Golem OEE MES software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-8464: Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by manipulating HTTP request paths.

    This issue has been fixed in version 11.6.0

    We thank Karol Królak (securitum.pl) for the responsible vulnerability report.

    Original source