CRITICAL
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations
Published Jan 15, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.56%
Description
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.
Affected products
-
Affected
- all versions
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Sick AG | Tdc-X401gl | affected | Affected
|
AND
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upon completion of the initial device setup, deactivate AppEngine. Disabling it fully mitigates this vulnerability.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2820 Advisory
- https://sick.com/psirt x_SICK PSIRT Security AdvisoriesVendor Advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices x_ICS-CERT recommended practices on Industrial SecurityUS Government Resource
- https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 CalculatorNot Applicable
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.json x_The canonical URL.Vendor Advisory
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf vendor-advisoryVendor Advisory
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf x_SICK Operating GuidelinesProduct
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2820 | Advisory | |
| https://sick.com/psirt | x_SICK PSIRT Security AdvisoriesVendor Advisory | |
| https://www.cisa.gov/resources-tools/resources/ics-recommended-practices | x_ICS-CERT recommended practices on Industrial SecurityUS Government Resource | |
| https://www.first.org/cvss/calculator/3.1 | x_CVSS v3.1 CalculatorNot Applicable | |
| https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.json | x_The canonical URL.Vendor Advisory | |
| https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf | vendor-advisoryVendor Advisory | |
| https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf | x_SICK Operating GuidelinesProduct |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SICK AG
Published Jan 15, 2026
Updated Jan 15, 2026
Reserved Jan 13, 2026
Link CVE-2026-22909
CISA Vulnrichment
Updated Jan 15, 2026
Red Hat
No data
GitHub
No data