← Vulnerability feed

Vulnerability record · CVE-2026-31156 · published 13 May 2026

CVE-2026-31156: Openplcproject openplc v3 firmware path traversal vulnerability

Openplcproject · Openplc V3 Firmware

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.

6.5 CVSS 3.1 Medium EPSS 0.46% · top 62.3% CWE-22 · Path traversal
6.5CVSS 3.1 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
5 Jul 2026Last modified by NVD

Description

A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file operation functions (fopen/ifstream/ofstream) for file reading and writing. An attacker can exploit this vulnerability by constructing a malicious path to read arbitrary readable files.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/unicorn-hyh/CVE-2026-31156 ExploitThird Party Advisory
https://github.com/unicorn-hyh/CVE-2026-31156 ExploitThird Party Advisory

Track CVE-2026-31156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34026Openplcproject openplc v3 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b454…EPSS 2.4%9.8CVE-2018-20818Openplcproject openplc v2 firmware memory buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapU…EPSS 1.5%9.2CVE-2026-35556Openplcproject openplc v3 firmware vulnerabilityOpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive…EPSS 0.40%9.2CVE-2026-28205Openplcproject openplc v3 firmware insecure default initialization vulnerabilityOpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…EPSS 0.67%8.8CVE-2021-31630Openplcproject openplc v3 firmware code injection vulnerabilityCommand Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har…EPSS 27%8.7CVE-2026-35063Openplcproject openplc v3 firmware missing authorization vulnerabilityOpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other…EPSS 0.43%7.5CVE-2024-39589Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%7.5CVE-2024-36981Openplcproject openplc v3 firmware out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2026-31156), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.