Junglewise Threat Intelligence

CVE-2026-46747: Siemens SINEC INS path traversal in SFTP uploadFiles endpoint

CVE-2026-46747 · Severity: medium · CVSS 4.3 · Published 2026-06-09

Technologies: Siemens Sinec Ins. Vendors: Siemens.

Executive brief

Siemens SINEC INS, a web-based application used to manage industrial network services, contains a security flaw in its file management interface. An authenticated user could exploit this to view files and directories on the system that they should not have access to. This could lead to the exposure of sensitive configuration data or system information.

Technical details

A path traversal vulnerability (CWE-26) exists in the `GET /api/sftp/uploadFiles` endpoint of Siemens SINEC INS. The application fails to properly sanitize path input used for directory listing operations. An authenticated remote attacker can provide crafted input (e.g., using dot-dot-slash sequences) to bypass intended directory restrictions and view the contents of arbitrary file system locations. This vulnerability is fixed in SINEC INS V1.0 SP2 Update 6.

Affected products

  • Siemens SINEC INS All versions < V1.0 SP2 Update 6

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory
  • 2026-06-09: patched: Fixed in V1.0 SP2 Update 6

References

Related threats