Siemens Siveillance Control Critical Vulnerability: Arbitrary File Upload Leads to Root Access
Siemens has identified a critical vulnerability in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro. Tracked as CVE-2026-50093, the flaw permits unrestricted file upload (CWE-434), enabling an attacker to upload arbitrary files and gain unauthorized root-level access on the OIS server. The vulnerability carries a CVSS v3.1 base score of 9.0 (CRITICAL). Affected versions include Siveillance Control Pro V3.0 before 3.0.12.2173, Siveillance Control Pro V4.0 before 4.0.9.2178, Siveillance Control V3.0 before 3.0.22.2177, and Siveillance Control V4.0 before 4.0.11.2177. Siemens has released vendor fixes and recommends updating to the latest patched versions. CISA has added the vulnerability to its ICS advisories and issued defensive guidance to minimize exploitation risk.




















