PatchSiren

thiagoralves CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL thiagoralves CVE published 2026-08-05

CVE-2026-71268

OpenPLC Runtime v3 is vulnerable to a path traversal attack in its compile_program() function, which allows remote code execution. The vulnerability exists due to the function's failure to validate file paths, enabling attackers to write content to arbitrary filesystem locations. This issue is exacerbated by the existence of a path-validation function that is not being utilized. Organizations using OpenPL [truncated]