CVE Explorer
CVE-2026-46746
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (s
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cvss · 2 assertions
{"metric":{"baseScore":8.7,"baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/metrics/1/cvssV4_0
{"metric":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/metrics/0/cvssV3_1
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"SINEC INS","vendor":"Siemens","versions":[{"lessThan":"V1.0 SP2 Update 6","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/affected/0
Provider-owned CVSS observations
2 source assertions{"metric":{"baseScore":8.7,"baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/metrics/1/cvssV4_0
{"metric":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://cert-portal.siemens.com/productcert/html/ssa-860189.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a047c408ad4bce717ed9e1ffeb2f150cbe67b6ff85b1090a4de94602b9decfe · sha256:21eb571af84c66d2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.