PT-2026-56921 · Unknown · Openplc Runtime

CVE-2026-14480

·

Published

2026-07-09

·

Updated

2026-07-12

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenPLC Runtime version 3
Description An authenticated arbitrary file write exists in the legacy web UI program-upload workflow. The application stores an attacker-supplied filename prog file into the Programs.File database field and uses this value as the destination path for an uploaded file without proper validation. Since Python os.path.join() honors absolute paths, an authenticated user can write files to any location writable by the webserver process. In default build pipelines, writing a malicious .cpp file into the runtime core directory allows an attacker to achieve arbitrary native code execution when a program compilation and runtime start are triggered. Real-world incidents have occurred where attackers exploited this issue to write malicious files, escalate privileges, and move laterally within industrial networks to disrupt control processes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement runtime segmentation to contain post-compromise activity across OT environments.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14480

Affected Products

Openplc Runtime