Status: UPDATED
| Advisory ID: CVE-2026-11841
Key Details
| CVE | CVE-2026-11841 |
| CVSS Score / Version | 9.4 (Critical) / CVSS v3.1 |
| Updated | 2026-09-09 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is low. |
| Affected products | see table below |
| Classified as | CWE-552 (Files or Directories Accessible to External Parties) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment. (NVD)
What to Do
Monitor Sick AG's web page for any future patch releases.
References