Critical File Upload Vulnerability in Siemens Siveillance Control Allows Root Access
A critical vulnerability in Siemens Siveillance Control and Siveillance Control Pro's Open Interface Services (OIS) web module allows attackers to upload arbitrary files, potentially leading to full system compromise.

Siemens has issued a critical security advisory detailing a vulnerability within the Open Interface Services (OIS) web module of its Siveillance Control and Siveillance Control Pro industrial control systems. The flaw, identified as CVE-2026-50093, resides in the OIS web module and could permit an attacker to upload arbitrary files to the affected server.
Successful exploitation of this vulnerability could grant an attacker unauthorized root-level access on the OIS server. This level of access would enable a complete compromise of the affected OIS environment, posing a significant risk to the operational integrity of systems relying on this Siemens software. The vulnerability has been rated as CRITICAL with a CVSS v3.1 base score of 9.0.
The affected products include specific versions of Siveillance Control Pro (V3.0 prior to 3.0.12.2173 and V4.0 prior to 4.0.9.2178) and Siveillance Control (V3.0 prior to 3.0.22.2177 and V4.0 prior to 4.0.11.2177). These systems are deployed globally across critical infrastructure sectors, including critical manufacturing and commercial facilities.
Siemens has responded by releasing patches and updates for the affected Siveillance OIS products. The company strongly recommends that users update to the latest available versions to mitigate the risk. Specific update links are provided for each affected product line within the advisory.
CISA has also issued a warning, urging users to take defensive measures to minimize exploitation risks. These recommendations include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and isolating control system networks behind firewalls. Secure remote access methods like VPNs are also advised, with a caution to keep them updated.
The vulnerability is categorized under CWE-434: Unrestricted Upload of File with Dangerous Type. This type of vulnerability often arises from insufficient validation of uploaded file types or content, allowing malicious executables or scripts to be introduced into a system.
This advisory highlights the ongoing security challenges within the industrial control systems (ICS) sector, where vulnerabilities can have far-reaching consequences due to the critical nature of the infrastructure they manage. Regular patching and robust network segmentation remain paramount for protecting these environments.