CVE-2026-46747: Path Traversal
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46747?
The severity of CVE-2026-46747 is rated as medium with a score of 4.3.
How do I fix CVE-2026-46747?
To fix CVE-2026-46747, update the SINEC INS application to version V1.0 SP2 Update 6 or later.
What types of attacks can CVE-2026-46747 facilitate?
CVE-2026-46747 can facilitate path traversal attacks due to improper input sanitization.
Which versions of Siemens SINEC INS are affected by CVE-2026-46747?
All versions of Siemens SINEC INS prior to V1.0 SP2 Update 6 are affected by CVE-2026-46747.
What is the impact of CVE-2026-46747 on system security?
CVE-2026-46747 allows unauthorized access to unintended files and directories, compromising system security.