Path Injection Vulnerability in OpenPLC Software
CVE-2026-31156
6.5MEDIUM
What is CVE-2026-31156?
A path injection vulnerability was identified in OpenPLC that allows unvalidated file path parameters to be exploited. The compiled binary from glue_generator.cpp fails to validate these parameters, enabling an attacker to pass malicious paths that can read arbitrary files from the system. This vulnerability poses a significant risk as it can lead to unauthorized access to sensitive data by leveraging user-controlled input.
