Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.
The following versions of OpenPLC Runtime v3 are affected:
OpenPLC 3 (CVE-2026-88020)
Vendor
Equipment
Autonomy Logic
OpenPLC Runtime v3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter wit...