---
id: CVE-2026-11841
title: >-
  An attacker may perform unauthenticated read and write operations on sensitive
  filesystem areas via the AppEngine Fileaccess over HTTP due to improper access
  restrictions
summary: >-
  An attacker may perform unauthenticated read and write operations on sensitive
  filesystem areas via the AppEngine Fileaccess over HTTP due to improper access
  restrictions. A critical filesystem directory was unintentionally exposed
  throu…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-552
published: '2026-07-28'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11841'
references:
  - url: 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices'
    label: psirt@sick.de
  - url: 'https://www.first.org/cvss/calculator/3.1'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf'
    label: psirt@sick.de
  - url: >-
      https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
    label: psirt@sick.de
  - url: 'https://www.sick.com/psirt'
    label: psirt@sick.de
tags:
  - nvd
epss: 0.00854
epssPercentile: 0.56503
ingestedAt: '2026-09-09T16:14:05.510Z'
---

## Overview

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
