Junglewise Threat Intelligence

CVE-2026-11841: SICK InspectorP6xx improper access control in AppEngine Fileaccess

CVE-2026-11841 · Severity: critical · CVSS 9.4 · Published 2026-07-28

Executive brief

SICK InspectorP6xx series industrial vision sensors are affected by a critical vulnerability in their AppEngine component. An unauthenticated attacker can remotely read and modify sensitive system files, including device configurations and user passwords. This could lead to a complete takeover of the device, unauthorized changes to industrial processes, or the execution of malicious code.

Technical details

The vulnerability is classified as CWE-552 (Files or Directories Accessible to External Parties) within the AppEngine Fileaccess over HTTP component. Improper access restrictions unintentionally expose critical filesystem directories to unauthenticated network users. An attacker can perform read and write operations on device parameter files to modify application settings and retrieve customer-defined passwords. Furthermore, by accessing the custom application directory, an attacker may be able to execute arbitrary Lua code within the sandboxed AppEngine environment. The vulnerability affects multiple InspectorP6xx models, with patches available for the P61x and P62x series (v5.4.0).

Affected products

  • SICK AG InspectorP61x < 5.4.0
  • SICK AG InspectorP62x < 5.4.0
  • SICK AG InspectorP63x all versions
  • SICK AG InspectorP64x all versions
  • SICK AG InspectorP65x all versions

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References