Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
Advisories

No advisories yet.

Fixes

Solution

Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).


Workaround

No workaround given by the vendor.

History

Thu, 15 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
Description Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2026-01-15T14:35:40.263Z

Reserved: 2026-01-08T09:59:06.199Z

Link: CVE-2026-22646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-15T14:16:28.430

Modified: 2026-01-15T14:16:28.430

Link: CVE-2026-22646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses