CVE-2026-2331Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-06); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-06: 5Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 103-0603-1003-11
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-065
Disclosure4General1
2026-03-101
Patch1
2026-03-111
Disclosure1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    SICK PSIRT warns of critical vulnerabilities (CVE-2026-2330, CVE-2026-2331) in Lector85x and Lector83x scanners allowing full device takeover. Update now #SICKLector #CVE20262331 #ICSSecurity #CyberSecurity #IndustrialAutomation #Vulnerability #PatchAlert https://securityonline.info/critical-9-8-cvss-flaws-expose-sick-lector-scanners-to-hijacking/ https://t.co/WdJPqdaQYs

    Post summary

    The SICK PSIRT alert warns of two critical Lector scanner vulnerabilities that enable full device takeover, urging immediate updates to mitigate the risk.

    01010333
    10.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2331 (CVSS:9.8, CRITICAL) is Awaiting Analysis. An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac..https://nvd.nist.gov/vuln/detail/CVE-2026-2331 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2331 as a critical vulnerability that allows unauthenticated read/write access to sensitive filesystem areas via AppEngine Fileac, but no proof of concept, exploit code, active exploitation evidence, or patch information is provided.

    0000037
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2331 An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictio… https://www.cve.org/CVERecord?id=CVE-2026-2331

    Post summary

    The post announces CVE-2026-2331, noting that unauthenticated file read/write can occur via AppEngine Fileaccess over HTTP due to improper access restrictions, but does not discuss PoC, active exploitation, or patches.

    00000134
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2331 Unauthenticated Filesystem Access and Arbitrary Code Execution in ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2331 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A newly disclosed vulnerability, CVE‑2026‑2331, permits unauthenticated filesystem access and arbitrary code execution. The post serves as a basic announcement without detailed exploits or mitigation information.

    0000052
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2331: CRITICAL] Critical file access vulnerability found in AppEngine enables unauthorized read/write to sensitive files over HTTP. Attackers can alter settings & passwords without authentication.#cve,CVE-2026-2331,#cybersecurity https://cvefind.com/CVE-2026-2331

    Post summary

    The text announces a critical file‑access vulnerability (CVE‑2026‑2331) in AppEngine that permits unauthorized read/write of sensitive files over HTTP, enabling attackers to modify settings and passwords.

    0000093
    597 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2331 Intel Report: https://ift.tt/LhmvIlj

    Post summary

    The tweet merely announces the existence of CVE-2026-2331 and points to an Intel report, without offering specific vulnerability details, patches, PoC, or exploitation evidence.

    0000035
    343 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2331 - Critical An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical files... https://www.thehackerwire.com/vulnerability/CVE-2026-2331/ https://t.co/PHImfsQs6G

    Post summary

    The tweet announces a newly disclosed vulnerability (CVE-2026-2331) in AppEngine’s Fileaccess, describing unauthenticated read/write capabilities due to improper access restrictions.

    0000038
    125 followersView on X

Explore more