FAIL › dossier
OpenPLC
VENDOR· dossier confidence 0%
OpenPLC is an open-source SCADA vendor with a critically poor security track record, repeatedly shipping software with high-severity vulnerabilities in its web management interface that enable remote code execution, path traversal, and XSS attacks, often remaining unpatched or exploited in the wild.
PROFILE
CategoryIndustrial Control System (ICS) / SCADA Software VendorWhat they doOpenPLC provides open-source SCADA and industrial control system software, including a runtime environment for uploading and compiling program files via a web-based portal.
SECURITY POSTURE
OpenPLC demonstrates a critically poor security posture, characterized by repeated high-severity vulnerabilities in its web-based management interface, including unpatched remote code execution (RCE) and cross-site scripting (XSS) flaws, alongside critical path traversal and arbitrary file write vulnerabilities that directly enable remote code execution.
Notable failures
- CVE-2021-26828: Arbitrary JSP execution RCE in ScadaBR
- CVE-2021-26829: Unpatched XSS exploited in the wild
- CVE-2026-71268: Arbitrary file write via path traversal enabling RCE
Patterns: Repeated unpatched or poorly patched web-interface vulnerabilities (RCE, XSS, path traversal); Failure to validate file paths in user-uploaded program files; Hardcoded default credentials in shipped software
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-12-03 | CVE-2021-26828 | high | OpenPLC ScadaBR exposed arbitrary JSP execution |
| 2025-11-28 | CVE-2021-26829 | high | OpenPLC ScadaBR had an unpatched XSS vulnerability exploited in the wild |
DOSSIER SOURCES
- CVE-2026-71268: OpenPLC Runtime Arbitrary File Write leading to Remote ... · cve.halosecurity.com
- CVE-2026-71268 | Path Traversal | CVETodo · cvetodo.com
- CVE-2026-71268 | CVE Alert & Security Feed · cvealert.net
Open questions: Current patch status for CVE-2021-26828 and CVE-2021-26829 · Whether newer versions of ScadaBR contain mitigations for these vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-09 05:01:02.187832+00:00