CVE-2026-50093

CRITICAL

View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . ...

Affects 0 products across 1 vendor.

CVSS 3.19.0
CVSS v48.9
EPSS0.3%
Percentile22th
PatchUnknown
CVSS Vector — Plain English Exploitable from adjacent network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-50093) affects the target system. A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versio...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-50093?
A critical severity vulnerability (CVE-2026-50093) affects the target system. A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versio...
What is the CVSS score for CVE-2026-50093?
CVE-2026-50093 has CVSS 9.0 (Critical). Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.3%.
Is CVE-2026-50093 actively exploited?
No confirmed active exploitation of CVE-2026-50093 as of 2026-09-23.
How do I remediate CVE-2026-50093?
Apply vendor patches for CVE-2026-50093. Monitor Siemens advisories.
What systems are affected by CVE-2026-50093?
CVE-2026-50093 affects: Siemens.
Vulnerability Details
CVE IDCVE-2026-50093
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published2026-09-08
Last Modified2026-09-22
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

View CSAF Summary A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions. T

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Siemens &mdash; —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 20 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Siemens
CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2026-56451 10.0 A vulnerability has been identified in Opcenter X (All versions < V2604). Aff... CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2008-6993 10.0 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allo... CVE-2011-4514 10.0 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →