CVE-2026-46747
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-26
- Published
- 2026-06-09
- Last modified
- 2026-06-09
Affected products
- Siemens SINEC INS
Weakness type
Related vulnerabilities
- CVE-2026-76317 — Path Traversal through the Lookup Configuration REST API in Splunk Enterprise
- CVE-2026-42196 — django-s3file: Relative path traversal
- CVE-2026-25575 — NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality
- CVE-2025-53908 — RomM vulnerable to Authenticated Path Traversal
- CVE-2025-25295 — Label Studio has a Path Traversal Vulnerability via image Field
- CVE-2024-5866 — Arbitrary Directory Listing in Centrify PAS
- CVE-2024-5865 — Arbitrary File Reading in Centrify PAS
- CVE-2024-20345 — A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an...