Critical Unrestricted File Upload in Siveillance Control
Siemens disclosed CVE-2026-50093, a critical vulnerability in the Open Interface Services (OIS) web module of its Siveillance Control and Siveillance Control Pro physical security management platforms. Successful exploitation can grant an attacker root access on the underlying host, opening the door to full compromise of the video and access-control environment.
Vulnerability Details
| Field | Detail |
|---|---|
| CVE ID | CVE-2026-50093 |
| Component | Siveillance Control / Control Pro — OIS web module |
| Weakness | CWE-434: Unrestricted Upload of File with Dangerous Type |
| CVSS 3.1 Score | 9.0 (Critical) — AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVSS 4.0 Score | 8.9 (High) |
| Reserved | 2026-06-03 |
| Published | 2026-09-08 |
| Assigner | Siemens ProductCERT |
The flaw allows an authenticated, low-privileged attacker on the adjacent network to upload a file of a dangerous type through the OIS web interface without adequate validation. Because the upload path runs with elevated permissions, a malicious file can be used to execute arbitrary code and pivot to root on the host running Siveillance Control.
Affected Products
- Siveillance Control Pro V3.0 — all versions ≤ V3.0.12.2173
- Siveillance Control Pro V4.0 — all versions ≤ V4.0.9.2178
- Siveillance Control V3.0 — all versions ≤ V3.0.22.2177
- Siveillance Control V4.0 — all versions ≤ V4.0.11.2177
Siveillance Control and Control Pro are used by enterprises, campuses, transit systems, and critical infrastructure operators to unify video management, access control, and intrusion detection into a single command-and-control layer — making a root-level compromise of the platform a direct path to disabling or manipulating physical security monitoring.
Why This Matters
Because the vulnerable component is a web-facing management interface, and because attack complexity is rated low with no user interaction required, this is a prime target for opportunistic scanning once technical detail on the file-upload path circulates. Siemens disclosed this advisory (tracked as SSA-254516) alongside a second critical flaw affecting Industrial Edge Management that permits full account takeover — both released the same day, September 8, 2026.
Remediation
Siemens has released fixed builds for all affected product lines:
- Update Siveillance Control to V3.0.22.2177 or V4.0.11.2177 or later
- Update Siveillance Control Pro to V3.0.12.2173 or V4.0.9.2178 or later
Interim Mitigations
If patching cannot happen immediately:
- Restrict network access to the OIS web module to trusted management VLANs only
- Disable or firewall the OIS web interface from any network segment that does not require it
- Monitor for unexpected file uploads or new executable files appearing on Siveillance hosts
- Follow Siemens' defense-in-depth guidance for industrial and building-security networks — segment operational systems from corporate IT and the internet
Recommendations for Organizations
- Inventory all Siveillance Control and Control Pro deployments and confirm installed version
- Apply the vendor patch during the next maintenance window — do not delay given the CVSS 9.0 rating
- Restrict OIS web module access to management networks only
- Review Siemens advisory SSA-254516 for the companion Industrial Edge Management flaw