Vulnerabilities · 16h ago

Siemens OIS File Upload Flaw Can Reach Root

CISA warned that a flaw in Siemens Siveillance Control and Siveillance Control Pro affects the Open Interface Services (OIS) web module and can let an attacker upload arbitrary files. Siemens and CISA tie the issue to CVE-2026-50093 and published fixed versions for the affected product lines.

The bug is a dangerous file-upload path in a web module: if the server accepts attacker-supplied content as usable, that content can cross from a simple upload into root-level access on the OIS host. In plain terms, a web form becomes a route to host compromise rather than just a place to store a file.

For operators running Siveillance Control in critical manufacturing, communications, or commercial facilities, the exposure sits at the service layer that fronts the system, not just inside the web module’s code. After patching, the remaining question is whether any OIS deployment was reachable before the fix and therefore subject to host-level takeover.

CVE-2026-50093

NVD KEV

CVSS 9 CRITICAL: a vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance… EPSS 0.2% (9th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories