VDB
CVE-2026-22644
CVE-2026-22644
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
EPSS 0.54% · 43.3th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.54%
43.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sick | incoming_goods_suite | |
| SICK AG | Incoming Goods Suite | all versions, all versions |
Timeline
- Jan 15, 2026 CVE Published
- Jan 15, 2026 CVE Updated
- Jan 15, 2026 PoC Published
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 26, 2026 EPSS Score
- Jan 30, 2026 EPSS Score
- Feb 2, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
- Feb 9, 2026 EPSS Score
- Feb 13, 2026 EPSS Score
References
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices advisory
- https://www.first.org/cvss/calculator/3.1 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-22644 advisory
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json url
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf vendor
- https://sick.com/psirt url
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf vendor-advisory