OpenPLC v3

Plan PatchCVSS 9.9ICS-CERT ICSA-26-190-01Jul 9, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An authenticated attacker can write arbitrary files to the OpenPLC filesystem and escalate this to arbitrary native code execution by injecting malicious code into the normal PLC program compilation process. This results in code execution running with OpenPLC runtime user privileges. OpenPLC v3 is end-of-life and no longer receiving security updates.

What this means
What could happen
An attacker with valid OpenPLC credentials could write malicious files to the system and inject them into the PLC program compilation process, gaining the ability to run arbitrary code on the OpenPLC runtime. This could allow complete control over the PLC logic that governs your manufacturing equipment.
Who's at risk
Manufacturing facilities using OpenPLC v3 for programmable logic control of production equipment, conveyor systems, motor drives, or other industrial automation components. Any site where OpenPLC manages critical process logic is at risk.
How it could be exploited
An attacker with valid OpenPLC user credentials uploads a malicious file through the OpenPLC interface to the filesystem. The attacker then crafts a PLC program that includes this file during the normal compilation process, injecting arbitrary code that executes when the compiled program runs on the OpenPLC runtime system.
Prerequisites
  • Valid OpenPLC user account credentials
  • Network access to OpenPLC web interface or API
  • Knowledge of OpenPLC project structure and compilation process
remotely exploitablelow complexityno patch available for v3 (end-of-life)affects operational control systems
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (1)
ProductAffected VersionsFix Status
OpenPLC: v3v3Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDUntil upgrade is complete, restrict OpenPLC user access to only trusted personnel with a documented business need
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade OpenPLC from v3 to v4 or later
Long-term hardening
0/1
HARDENINGSegment OpenPLC systems onto a dedicated network with strict firewall rules allowing access only from authorized engineering workstations
API: /api/v1/advisories/52e9e383-01b9-4d62-a45e-14860c1e42f4

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

OpenPLC v3 | CVSS 9.9 - OTPulse