
CVE-2026-35063 OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including … https://www.cve.org/CVERecord?id=CVE-2026-35063
Post summary
CVE-2026-35063 reveals a role‑verification flaw in OpenPLC_V3’s REST API, allowing any authenticated user with role ‘user’ to delete other users.
