Plaintext Storage Vulnerability in OpenPLC_V3 by OpenPLC Project
CVE-2026-35556

9.2CRITICAL

Key Information:

Vendor

Openplc V3

Vendor
CVE Published:
9 April 2026

What is CVE-2026-35556?

OpenPLC_V3 contains a vulnerability that allows passwords to be stored in plaintext. This weakness can be exploited by attackers to retrieve sensitive credentials, potentially compromising system integrity and leading to unauthorized access to critical information.

Affected Version(s)

OpenPLC_V3 All versions

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shriyans Sudhi (ss0x00) from Rochester Institute of Technology (RIT)
.