Built from approved structured facts. Every conclusion below carries evidence references.
Corroborated brief
1
Finding
indicator:193036:description
What happened
NVD describes CVE-2026-14480 as: OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy web UI program‑upload workflow. The
application stores an attacker‑supplied filename (prog_file) directly
into the Programs.File database field and later uses this value as the
destination path for an uploaded file without validating or restricting
the path. Because Python os.path.join() honors attacker‑controlled
absolute paths, an authenticated user can write arbitrary files anywhere
writable by the OpenPLC webserver process. In the default build
pipeline, all C++ source files within the OpenPLC runtime core directory
are automatically compiled into the executable runtime binary. By
writing a malicious .cpp file into this directory, an authenticated
attacker can escalate the arbitrary file write into arbitrary native
code execution when the operator triggers a normal program compilation
and runtime start.
Scroll this evidence note to continue
2
Impact
indicator:193036:cvsscisa-kev:CVE-2026-14480
Why it matters
NVD assigns CVE-2026-14480 a CVSS base score of 9.9. CISA lists CVE-2026-14480 in the Known Exploited Vulnerabilities catalog.
Check whether the affected product and version are present in your environment, then follow the vendor or NVD remediation guidance for CVE-2026-14480.
publisher text · intentionally withheld
The original article remains with its publisher
This source is currently approved for metadata display only. The structured panel above shows only facts that Forensia can lawfully support. Its status will advance automatically when approved evidence becomes available.
Grouping means the records share event anchors. It does not prove that every publisher independently verified the claims.
rights & provenance
PublisherCISA Cybersecurity Advisories
Display policymetadata only
Rights reviewpending
Reader materiallegacy
CapturedJul 9, 2026
Integritysha256:fa9461a365a1a23db1…
Coverage state measures available context, not whether every claim is true or independently corroborated. Unknown publication rights fail closed to metadata and the original source link.