PT-2026-47733 · Siemens · Sinec Ins

CVE-2026-46747

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SINEC INS versions prior to V1.0 SP2 Update 6
Description The application fails to properly sanitize path input in the 'GET /api/sftp/uploadFiles' endpoint used for directory listing. This allows path traversal, a technique used to access files and directories that are stored outside the web root folder, by using crafted input to reach unintended file system locations.
Recommendations Update to V1.0 SP2 Update 6 or a newer version. As a temporary workaround, restrict access to the 'GET /api/sftp/uploadFiles' endpoint to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08432
BDU:2026-08433
CVE-2026-46747

Affected Products

Sinec Ins