VORANT. Threat Intelligence Sign in Get the full feed

OpenPLC v3 file write flaw enables code execution

medium vulnerability manufacturingenergytransportationinfrastructure

An authenticated arbitrary file write bug in end-of-life OpenPLC v3's web UI can be escalated to arbitrary code execution via the runtime compilation process.

CISA has published an advisory for OpenPLC Runtime v3, an open-source programmable logic controller platform used across critical manufacturing, energy, transportation, and water/wastewater sectors worldwide. The vulnerability, tracked as CVE-2026-14480, stems from the legacy web UI's program-upload workflow, which stores an attacker-supplied filename directly into a database field and later uses it as a destination path without validation. Because Python's os.path.join() honors attacker-controlled absolute paths, an authenticated user can write files anywhere the OpenPLC webserver process has permission to write.

The more serious risk is escalation: the default OpenPLC build pipeline automatically compiles all C++ source files found in the runtime core directory into the executable binary. An attacker who writes a malicious .cpp file into that directory can achieve arbitrary native code execution as the OpenPLC runtime user simply by waiting for an operator to trigger a normal program compilation and runtime start — no additional exploitation primitives are needed.

OpenPLC v3 is end-of-life and will not receive a patch; the vendor's only remediation is migration to OpenPLC v4. CISA reports no known public exploitation at this time and recommends standard ICS network segmentation, firewalling, and secure remote access practices (VPNs) as compensating controls given the lack of a fix.

Mentioned in this report

Vulnerabilities CVE-2026-14480

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free