CVE-2026-11841
Received Received - Intake

Unauthenticated File Access in AppEngine

Vulnerability report for CVE-2026-11841, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: SICK AG

Description

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
sick inspectorp61x 5.4.0
sick inspectorp62x 5.4.0
sick inspectorp63x *
sick inspectorp64x *
sick inspectorp65x *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-11841 is a critical vulnerability in SICK InspectorP6xx devices where an attacker can perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP. This occurs due to improper access restrictions, exposing critical directories like device parameter files and custom application directories. Attackers can read and modify application settings, including passwords, and execute arbitrary Lua code within the sandboxed environment.

Detection Guidance

Detect this vulnerability by checking if SICK InspectorP6xx devices are running affected firmware versions (P61x/P62x below 5.4.0 or any P63x/P64x/P65x firmware). Scan for exposed HTTP-based file access endpoints on these devices. Verify if internal filesystem paths are accessible without authentication.

Impact Analysis

This vulnerability allows unauthenticated attackers to read and modify device configurations, including passwords, leading to unauthorized changes. It can cause Denial of Service (DoS), expose sensitive system information, and potentially facilitate full device compromise. Attackers can also execute arbitrary code, further compromising the device and network.

Mitigation Strategies

Upgrade affected devices to firmware version 5.4.0 or later for P61x/P62x models. For P63x/P64x/P65x, restrict network access to trusted entities and minimize exposure. Implement strict network controls and follow industrial security best practices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11841. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart