SINEC INS < V1.0 SP2 U6: /api/sftp/uploadFiles Shell Injection
CVE-2026-46746 Published on June 9, 2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-46746 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-46746
Want to know whenever a new CVE is published for Siemens Sinec Ins? stack.watch will email you.
Affected Versions
Siemens SINEC INS:- Before V1.0 SP2 Update 6 is affected.