---
id: CVE-2026-80469
title: >-
  An attacker may achieve arbitrary code execution on a target system by
  uploading a malicious device driver package, bypassing driver verification
  mechanisms, and triggering the execution of

  attacker-controlled code
summary: >-
  An attacker may achieve arbitrary code execution on a target system by
  uploading a malicious device driver package, bypassing driver verification
  mechanisms, and triggering the execution of

  attacker-controlled code. User interaction is r…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: SICK AG
product: Sentio Creator Extension 'Device Manager'
affected:
  - sentio_creator_extension_device_manager <= 1.4
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:25:29.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80469'
references:
  - url: 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices'
    label: psirt@sick.de
  - url: 'https://www.first.org/cvss/calculator/3.1'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0012.json'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0012.pdf'
    label: psirt@sick.de
  - url: >-
      https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
    label: psirt@sick.de
  - url: 'https://www.sick.com/psirt'
    label: psirt@sick.de
tags:
  - nvd
  - cve.org
epss: 0.0023
epssPercentile: 0.14075
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T13:55:32.686810Z'
ingestedAt: '2026-09-11T16:45:47.860Z'
---

## Overview

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
