What is CVE-2026-71268?
CVE-2026-71268 is a path traversal vulnerability in OpenPLC Runtime v3's `compile_program()` function when parsing `(*FILE:path content*)` directives in uploaded .st files. This could allow an unauthenticated remote attacker to write files outside the intended `./core` directory. Users should immediately apply the security update and restrict uploads of untrusted program files.
Azərbaycanca: CVE-2026-71268 OpenPLC Runtime v3-də `compile_program()` funksiyasının yüklənmiş .st fayllarında `(*FILE:path content*)` direktivlərini işləyərkən path traversal zəifliyidir. Bu, autentifikasiya olunmamış uzaq hücumçuya `./core` qovluğundan kənarda fayl yazmağa imkan verə bilər. İstifadəçilər dərhal təhlükəsizlik yeniləməsini tətbiq etməli və şübhəli proqram fayllarının yüklənməsini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which function does the CVE-2026-71268 vulnerability affect in OpenPLC Runtime v3?
The CVE-2026-71268 vulnerability affects the `compile_program()` function in OpenPLC Runtime v3.
What can an attacker exploiting CVE-2026-71268 do on the target system?
The CVE-2026-71268 vulnerability could allow an unauthenticated remote attacker to write files outside the intended `./core` directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.