CISA

OpenPLC Runtime v3

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

The following versions of OpenPLC Runtime v3 are affected:

OpenPLC 3 (CVE-2026-88020)

Vendor

Equipment

Autonomy Logic

OpenPLC Runtime v3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Critical Infrastructure Sectors: Critical Manufacturing, Energy, Transportation Systems, Water and Wastewater Systems

Countries/Areas Deployed: Worldwide

Company Headquarters Location: United States

The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter wit...