← All Advisories

CVE-2026-46748

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-46748

Key Details

CVECVE-2026-46748
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSiemens sinec_ins and Siemens SINEC INS
Classified asCWE-250 (Execution with Unnecessary Privileges)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Siemenssinec_ins
SiemensSINEC INS
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system. (NVD)

What to Do

Monitor Siemens's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-46748
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-46748
Vendor advisoryhttps://cert-portal.siemens.com/productcert/html/ssa-860189.html