Session Hijacking Vulnerability in SICK Products
CVE-2026-22644

5.3MEDIUM

Key Information:

Vendor

Sick Ag

Vendor
CVE Published:
15 January 2026

What is CVE-2026-22644?

Certain requests within SICK products are improperly configured, transmitting the authentication token as a string query parameter in the URL. This configuration makes the token vulnerable to exposure through server logs, proxy logs, and Referer headers. If exploited, this vulnerability could enable an attacker to hijack a user's session, potentially allowing unauthorized access to sensitive data and functionalities.

Affected Version(s)

Incoming Goods Suite all versions

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.