Error Exposure in SICK Products Leads to Security Risks
CVE-2026-22646

4.3MEDIUM

Key Information:

Vendor

Sick Ag

Vendor
CVE Published:
15 January 2026

What is CVE-2026-22646?

An issue exists in certain SICK products where error messages inadvertently expose sensitive internal system details. These messages may reveal crucial information such as file paths, database errors, or software versions. Such disclosures pose a significant risk, as they can help malicious actors create a map of the application's internal architecture, potentially leading to the discovery of further vulnerabilities that could be exploited.

Affected Version(s)

Incoming Goods Suite 0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.