PT-2026-56921 · Unknown · Openplc Runtime
CVE-2026-14480
·
Published
2026-07-09
·
Updated
2026-07-12
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenPLC Runtime version 3
Description
An authenticated arbitrary file write exists in the legacy web UI program-upload workflow. The application stores an attacker-supplied filename
prog file into the Programs.File database field and uses this value as the destination path for an uploaded file without proper validation. Since Python os.path.join() honors absolute paths, an authenticated user can write files to any location writable by the webserver process. In default build pipelines, writing a malicious .cpp file into the runtime core directory allows an attacker to achieve arbitrary native code execution when a program compilation and runtime start are triggered. Real-world incidents have occurred where attackers exploited this issue to write malicious files, escalate privileges, and move laterally within industrial networks to disrupt control processes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Implement runtime segmentation to contain post-compromise activity across OT environments.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openplc Runtime