CVE-2026-8047: Out-of-bounds Write in CODESYS Control
Published May 26, 2026
·Updated
The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.
Affected Software
1 affected component
CODESYS CODESYS Control
Event History
May 26, 2026
CVE Published
via MITRE·06:49 AM
Data Sourced
via MITRE·06:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Sep 24, 58369
Event
via NVD·07:23 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-8047?
CVE-2026-8047 has a severity rating of 7.5, classified as high.
2
What type of vulnerability is CVE-2026-8047?
CVE-2026-8047 is an out-of-bounds write vulnerability affecting CODESYS Control.
3
How do I fix CVE-2026-8047?
To fix CVE-2026-8047, apply the latest patches provided by CODESYS.
4
What could happen if CVE-2026-8047 is exploited?
Exploitation of CVE-2026-8047 could lead to a denial of service by causing a system crash.
5
Who is affected by CVE-2026-8047?
CVE-2026-8047 affects users of CODESYS Control software.