216.73.217.22

CVE-2026-46747

· Published 09/06/2026 10:16 · Modified 09/06/2026 13:49

Labels: CVE-2026-46747 2026-06-09CVE-2026-46747CWE-26[email protected]

Essential information

Published
09/06/2026 10:16
Modified
09/06/2026 13:49
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
siemens / sinec ins cpe:2.3:a:siemens:sinec_ins:<V1.0 SP2 Update 6:*:*:*:*:*:*:*

References