CVE-2026-46748: High severity Siemens Sinec Ins vulnerability
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the capdacoverride capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SINEC INSto a version that resolves this vulnerability.Fixed in V1.0 SP2 Update 6 - Configuration
Remove the cap_dac_override capability from the affected binary so the process cannot bypass file system permission checks. If possible, apply the vendor-provided update (V1.0 SP2 Update 6) instead.
SINEC INS affected binary cap_dac_override capability = removed
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46748?
The severity of CVE-2026-46748 is classified as high, with a CVSS score of 8.8.
What impact does CVE-2026-46748 have on my system?
CVE-2026-46748 allows processes to bypass file system permission checks, resulting in unrestricted file system access.
How do I fix CVE-2026-46748?
To fix CVE-2026-46748, upgrade to Siemens SINEC INS version 1.0 SP2 Update 6 or later.
Who is affected by CVE-2026-46748?
All versions of Siemens SINEC INS prior to V1.0 SP2 Update 6 are affected by CVE-2026-46748.
What are the potential risks of not addressing CVE-2026-46748?
Failing to address CVE-2026-46748 could lead to unauthorized access and manipulation of sensitive files on the affected system.