← All Advisories

CVE-2026-11841

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-11841

Key Details

CVECVE-2026-11841
CVSS Score / Version9.4 (Critical) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is low.
Affected productssee table below
Classified asCWE-552 (Files or Directories Accessible to External Parties)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Sick AGInspectorP61x
Sick AGInspectorP62x
Sick AGInspectorP65x
Sick AGInspectorP63x
Sick AGInspectorP64x
Sick AGICR890-4
SubsystemsGeneral OT
SectorsMultiple

What to Know

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment. (NVD)

What to Do

Monitor Sick AG's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-11841
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-11841