← All Advisories

CVE-2026-8047

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-8047

Key Details

CVECVE-2026-8047
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-1284 (Improper Validation of Specified Quantity in Input)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
CODESYSCODESYS Control RTE (SL)
CODESYSCODESYS Control RTE (for Beckhoff CX) SL
CODESYSCODESYS Control Win (SL)
CODESYSCODESYS HMI (SL)
CODESYSCODESYS Runtime Toolkit
CODESYSCODESYS Control for BeagleBone SL
CODESYSCODESYS Control for emPC-A/iMX6 SL
CODESYSCODESYS Control for IOT2000 SL
CODESYSCODESYS Control for Linux ARM SL
CODESYSCODESYS Control for Linux SL
CODESYSCODESYS Control for PFC100 SL
CODESYSCODESYS Control for PFC200 SL
CODESYSCODESYS Control for PLCnext SL
CODESYSCODESYS Control for Raspberry Pi SL
CODESYSCODESYS Control for WAGO Touch Panels 600 SL
CODESYSCODESYS Virtual Control SL
SubsystemsGeneral OT
SectorsMultiple

What to Know

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device. (NVD)

What to Do

Monitor CODESYS's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8047
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8047