CVE-2026-22646

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sick:incoming_goods_suite:*:*:*:*:*:*:*:*

History

29 Jan 2026, 16:18

Type Values Removed Values Added
CPE cpe:2.3:a:sick:incoming_goods_suite:*:*:*:*:*:*:*:*
First Time Sick
Sick incoming Goods Suite
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json - () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf - () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf - Vendor Advisory
References () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - Product

15 Jan 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 14:16

Updated : 2026-01-29 16:18


NVD link : CVE-2026-22646

Mitre link : CVE-2026-22646

CVE.ORG link : CVE-2026-22646


JSON object : View

Products Affected

sick

  • incoming_goods_suite
CWE
CWE-209

Generation of Error Message Containing Sensitive Information