Remote Code Execution Vulnerability in OpenPLC Runtime by Thiago Alves
CVE-2026-71268

9.9CRITICAL

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-71268?

The OpenPLC Runtime version 3 contains a vulnerability in its compile_program() function, which improperly handles directives in uploaded Structured Text programs. Specifically, it fails to validate the file_path used to write content, allowing attackers to exploit this flaw and potentially execute arbitrary code. This could be achieved through crafted .st files that direct the program to arbitrary file system paths, compromising system integrity. The presence of hardcoded default credentials further escalates the risk, making exploitation feasible for attackers.

Affected Version(s)

OpenPLC_v3 0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.