CRITICAL
thiagoralves
CVE published 2026-08-05
CVE-2026-71268
OpenPLC Runtime v3 is vulnerable to a path traversal attack in its compile_program() function, which allows remote code execution. The vulnerability exists due to the function's failure to validate file paths, enabling attackers to write content to arbitrary filesystem locations. This issue is exacerbated by the existence of a path-validation function that is not being utilized. Organizations using OpenPL [truncated]