CVE-2026-46746
CVSS 8.8 HIGH: a vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). EPSS 0.4% (35th percentile).
Vulnerabilities · 83 days ago
A successful login to SINEC INS before V1.0 SP2 Update 6 can cross from the web app into the host itself. The issue is not just bad input handling at the interface; one flaw can turn the service account into a command runner on the underlying operating system, and another opens unintended file-system access.
CISA says Siemens SINEC INS before V1.0 SP2 Update 6 is affected by multiple flaws, including authenticated OS command injection, path traversal, excessive privileges, and weak password hashing. Siemens has released V1.0 SP2 Update 6, and the affected footprint includes critical manufacturing, transportation, energy, healthcare, financial services, and government deployments worldwide.
CVSS 8.8 HIGH: a vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). EPSS 0.4% (35th percentile).
CVSS 4.3 MEDIUM: a vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). EPSS 0.2% (15th percentile).
CVSS 8.8 HIGH: a vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). EPSS 0.2% (11th percentile).
CVSS 7.5 HIGH: a vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). EPSS 0.1% (2nd percentile).
1 source covering this story
Siemens SINEC INS Summary SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities.
Part of the PlainSec briefing for 2026-06-23