{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-11841","assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","state":"PUBLISHED","assignerShortName":"SICK AG","dateReserved":"2026-06-10T06:53:18.277Z","datePublished":"2026-07-28T09:25:36.738Z","dateUpdated":"2026-07-28T19:15:14.851Z"},"containers":{"cna":{"providerMetadata":{"orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG","dateUpdated":"2026-07-28T09:25:36.738Z"},"title":"CVE-2026-11841","datePublic":"2026-07-28T10:47:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-552","description":"CWE-552 Files or directories accessible to external parties","type":"CWE"}]}],"affected":[{"vendor":"SICK AG","product":"InspectorP61x","versions":[{"status":"affected","version":"0","lessThan":"5.4.0","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"SICK AG","product":"InspectorP62x","versions":[{"status":"affected","version":"0","lessThan":"5.4.0","versionType":"custom"}],"defaultStatus":"affected"},{"vendor":"SICK AG","product":"InspectorP65x","versions":[{"status":"affected","version":"all versions"}],"defaultStatus":"affected"},{"vendor":"SICK AG","product":"InspectorP63x","versions":[{"status":"affected","version":"all versions"}],"defaultStatus":"affected"},{"vendor":"SICK AG","product":"InspectorP64x","versions":[{"status":"affected","version":"all versions"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.</p>"}]}],"references":[{"url":"https://www.sick.com/psirt","tags":["x_SICK PSIRT Security Advisories"]},{"url":"https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf","tags":["x_SICK Operating Guidelines"]},{"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices","tags":["x_ICS-CERT recommended practices on Industrial Security"]},{"url":"https://www.first.org/cvss/calculator/3.1","tags":["x_CVSS v3.1 Calculator"]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json","tags":["x_The canonical URL."]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseSeverity":"CRITICAL","baseScore":9.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}}],"source":{"discovery":"INTERNAL","advisory":"SCA-2026-0010"},"x_generator":{"engine":"Vulnogram 1.0.4"},"solutions":[{"lang":"en","value":"InspectorP61x and InspectorP62x users are recommended to upgrade to version 5.4.0.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><span>InspectorP61x and InspectorP62x u</span>sers are recommended to upgrade to version 5.4.0.</div>"}]}],"workarounds":[{"lang":"en","value":"Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources ”SICK Operating Guidelines” and ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><div>Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources ”SICK Operating Guidelines” and ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.</div></div>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-28T19:13:27.519553Z","id":"CVE-2026-11841","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-28T19:15:14.851Z"}}]}}