Remote Code Execution Vulnerability in OpenPLC Runtime by Thiago Alves
CVE-2026-71268
9.9CRITICAL
What is CVE-2026-71268?
The OpenPLC Runtime version 3 contains a vulnerability in its compile_program() function, which improperly handles directives in uploaded Structured Text programs. Specifically, it fails to validate the file_path used to write content, allowing attackers to exploit this flaw and potentially execute arbitrary code. This could be achieved through crafted .st files that direct the program to arbitrary file system paths, compromising system integrity. The presence of hardcoded default credentials further escalates the risk, making exploitation feasible for attackers.
Affected Version(s)
OpenPLC_v3 0
