Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a critical missing authentication vulnerability (CVE-2026-58115) in the Node-RED HTTP interface. An unauthenticated remote attacker can exploit this flaw to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. The vulnerability received a CVSS v3.1 base score of 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Affected versions are SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) running versions prior to V4.3.4.1. The vulnerability affects critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Transportation Systems worldwide. Siemens has released version V4.3.4.1 as a fix, and interim mitigations include hardening the Node-RED installation or uninstalling Node-RED entirely. The vulnerability was reported by Siemens ProductCERT to CISA.