Improper Access Control in AppEngine Fileaccess by SICK
CVE-2026-11841
9.4CRITICAL
Key Information:
- Vendor
Sick Ag
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-11841?
An improper access control vulnerability in SICK's AppEngine allows attackers to perform unauthenticated read and write operations on sensitive filesystem components through HTTP. This exposure leads to the unintended accessibility of critical directory files, including device parameter files, enabling attackers to manipulate application settings and potentially execute arbitrary Lua code within the AppEngine's sandbox environment. The flaw arises from insufficient access restrictions for the HTTP-based file access feature, posing significant risks to application integrity and security.
Affected Version(s)
InspectorP61x 0
InspectorP62x 0
InspectorP63x all versions
