Junglewise Threat Intelligence

CVE-2026-8047: CODESYS Control out-of-bounds write in CmpWebServer

CVE-2026-8047 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: CODESYS.

Executive brief

A vulnerability exists in the web server component of CODESYS Control, a software suite used to manage industrial automation and control systems. An attacker can send a malicious web request to crash the system, leading to a complete shutdown of industrial processes and monitoring tools. This could result in operational downtime and loss of control over connected machinery until the system is manually restarted.

Technical details

The vulnerability is an out-of-bounds write (CWE-1284) within the CmpWebServer component of the CODESYS Control Runtime. It is caused by improper length validation when parsing incoming HTTP requests. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the device. Successful exploitation results in a system crash and denial of service. The vulnerability only affects systems where the Web Visualization feature is enabled and the web server is active. Patches are available for several versions, with others expected in June 2026.

Affected products

  • CODESYS Control RTE (SL) 3.5.21.0 to 3.5.22.20
  • CODESYS Control Win (SL) 3.5.21.0 to 3.5.22.20
  • CODESYS Control for Linux SL 4.15.0.0 to 4.21.0.0
  • CODESYS Control for Raspberry Pi SL 4.15.0.0 to 4.21.0.0
  • CODESYS HMI (SL) 3.5.21.0 to 3.5.22.20

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory

References