← Vulnerability feed

Vulnerability record · CVE-2026-35556 · published 9 April 2026

CVE-2026-35556: Openplcproject openplc v3 firmware vulnerability

Openplcproject · Openplc V3 Firmware

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

9.2 CVSS 4.0 Critical EPSS 0.40% · top 68.0% CWE-256 · CWE-256
9.2CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-10 Third Party AdvisoryUS Government Resource

Track CVE-2026-35556 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34026Openplcproject openplc v3 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b454…EPSS 2.4%9.8CVE-2018-20818Openplcproject openplc v2 firmware memory buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapU…EPSS 1.5%9.2CVE-2026-28205Openplcproject openplc v3 firmware insecure default initialization vulnerabilityOpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…EPSS 0.67%8.8CVE-2021-31630Openplcproject openplc v3 firmware code injection vulnerabilityCommand Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har…EPSS 27%8.7CVE-2026-35063Openplcproject openplc v3 firmware missing authorization vulnerabilityOpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other…EPSS 0.43%7.5CVE-2024-36981Openplcproject openplc v3 firmware out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298…EPSS 1.0%7.5CVE-2024-39589Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%7.5CVE-2024-39590Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2026-35556), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.