


Perceptive Security
SOC/SIEM Consultancy

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access re…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 11:00:57
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities, Identity & Access
CVE-2026-11841 is a critical vulnerability in SICK's AppEngine Fileaccess feature that allows unauthenticated read and write operations on sensitive filesystem areas via HTTP. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, bypassing authentication entirely. Attackers can access and modify device parameter files, including customer-defined passwords and application settings. Furthermore, exposure of the custom application directory may enable execution of arbitrary Lua code within the sandboxed AppEngine environment. The vulnerability stems from improper access restrictions in the HTTP-based file access mechanism. SICK has published an advisory (SCA-2026-0010) and associated documentation addressing the issue. References include CISA ICS recommended practices and CVSS 3.1 scoring resources. The vulnerability poses significant risk to industrial and operational technology environments where SICK devices are deployed.
Technical details
Mitigation steps:
Affected products:
SICK AppEngine
SICK AppEngine Fileaccess
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-11841
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
https://www.first.org/cvss/calculator/3.1
https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json
https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf
https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
https://www.sick.com/psirt
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
