CVE-2026-22646

MEDIUM

Sick Incoming Goods Suite < 1.2.1 - Error Information Exposure

Title source: rule
STIX 2.1

Description

Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.

Scores

CVSS v3 4.3
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
sick/incoming_goods_suite < 1.2.1
Published Jan 15, 2026
Tracked Since Feb 18, 2026