Skip to content
COOEY

FAIL › dossier

OpenPLC

VENDOR

· dossier confidence 0%

OpenPLC is an open-source SCADA vendor with a critically poor security track record, repeatedly shipping software with high-severity vulnerabilities in its web management interface that enable remote code execution, path traversal, and XSS attacks, often remaining unpatched or exploited in the wild.

PROFILE
CategoryIndustrial Control System (ICS) / SCADA Software VendorWhat they doOpenPLC provides open-source SCADA and industrial control system software, including a runtime environment for uploading and compiling program files via a web-based portal.
SECURITY POSTURE

OpenPLC demonstrates a critically poor security posture, characterized by repeated high-severity vulnerabilities in its web-based management interface, including unpatched remote code execution (RCE) and cross-site scripting (XSS) flaws, alongside critical path traversal and arbitrary file write vulnerabilities that directly enable remote code execution.

Notable failures
  • CVE-2021-26828: Arbitrary JSP execution RCE in ScadaBR
  • CVE-2021-26829: Unpatched XSS exploited in the wild
  • CVE-2026-71268: Arbitrary file write via path traversal enabling RCE
Patterns: Repeated unpatched or poorly patched web-interface vulnerabilities (RCE, XSS, path traversal); Failure to validate file paths in user-uploaded program files; Hardcoded default credentials in shipped software
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-12-03 CVE-2021-26828 high OpenPLC ScadaBR exposed arbitrary JSP execution
2025-11-28 CVE-2021-26829 high OpenPLC ScadaBR had an unpatched XSS vulnerability exploited in the wild
Open questions: Current patch status for CVE-2021-26828 and CVE-2021-26829 · Whether newer versions of ScadaBR contain mitigations for these vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-09 05:01:02.187832+00:00