top of page
perceptive_background_267k.jpg

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access re…

Published:

28 juli 2026 om 00:00:00

Alert date:

28 juli 2026 om 13:00:57

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities, Identity & Access

CVE-2026-11841 is a critical vulnerability in SICK's AppEngine Fileaccess feature that allows unauthenticated read and write operations on sensitive filesystem areas via HTTP. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, bypassing authentication entirely. Attackers can access and modify device parameter files, including customer-defined passwords and application settings. Furthermore, exposure of the custom application directory may enable execution of arbitrary Lua code within the sandboxed AppEngine environment. The vulnerability stems from improper access restrictions in the HTTP-based file access mechanism. SICK has published an advisory (SCA-2026-0010) and associated documentation addressing the issue. References include CISA ICS recommended practices and CVSS 3.1 scoring resources. The vulnerability poses significant risk to industrial and operational technology environments where SICK devices are deployed.

Technical details

Mitigation steps:

Affected products:

SICK AppEngine
SICK AppEngine Fileaccess

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page