CVE-2026-46747
Description
SINEC INS versions prior to V1.0 SP2 Update 6 are vulnerable to path traversal via the GET /api/sftp/uploadFiles endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SINEC INS versions prior to V1.0 SP2 Update 6 are vulnerable to path traversal via the `GET /api/sftp/uploadFiles` endpoint.
Vulnerability
A path traversal vulnerability exists in SINEC INS versions prior to V1.0 SP2 Update 6. The GET /api/sftp/uploadFiles endpoint does not properly sanitize path input, allowing attackers to access unintended file system locations [1].
Exploitation
An attacker can exploit this vulnerability by sending crafted input to the GET /api/sftp/uploadFiles endpoint. Network access to the affected application is required, and no specific authentication or user interaction is mentioned as necessary in the available references [1].
Impact
Successful exploitation of this vulnerability allows an attacker to perform path traversal, potentially leading to unauthorized access to sensitive files or directories on the file system. The exact scope and impact depend on the privileges of the SINEC INS application on the host system [1].
Mitigation
Siemens has released SINEC INS V1.0 SP2 Update 6 as a remediation for this vulnerability. Users are recommended to update to V1.0 SP2 Update 6 or a later version. The update is available via the provided Siemens support link [1].
AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <V1.0 SP2 Update 6
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Siemens SINEC INS: Six Vulnerabilities Disclosed, Including High-Severity FlawsVypr Intelligence · Jun 9, 2026