IM
IronMonkey Threat Research
‹ Back to ICS Advisories

OpenPLC Runtime v3

MEDIUM
CVSS 6.1
Date 2026-09-22T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-88020 6.1 medium
The affected product is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Autonomy Logic Unknown plc
L1
3

// Remediations (1)

Patch: Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer
Autonomy Logic recommends users upgrade to OpenPLC v4 as OpenPLC v3 is end-of-life and is no longer receiving patches, bug fixes, or security updates.

// References