CVE-2026-46746 Details
Description
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).
A command injection vulnerability has been identified in Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The issue arises in the SFTP file upload API endpoint, where user input is not properly sanitized. This lack of input validation allows authenticated remote attackers to inject shell command payloads through manipulated directory names. These injected commands are stored and executed when directory listings are accessed, potentially leading to arbitrary command execution on the underlying operating system with the privileges of the affected service user.
Users are advised to update to Siemens SINEC INS version V1.0 SP2 Update 6 or later. For more information, visit the Siemens Industry Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-860189.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens sinec ins | <= 1.0 1.0 sp1 1.0 sp2 1.0 sp2_update_1 1.0 sp2_update_2 1.0 sp2_update_3 1.0 sp2_update_4 1.0 sp2_update_5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2026 | New CVE Received | [email protected] |