
CVE-2026-88020 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the p… https://www.cve.org/CVERecord?id=CVE-2026-88020
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-88020 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the p… https://www.cve.org/CVERecord?id=CVE-2026-88020

🔴 OpenPLC Runtime v3 flaw lets attackers hijack operator sessions, control industrial systems A cross-site scripting vulnerability (CVE-2026-88020) in OpenPLC Runtime v3 allows attackers to steal session cookies and issue commands as an operator, gaining control over programmable logic controllers and their connected physical processes. The vulnerability stems from improper input neutralization in the web interface's query string routing, leaving it unencoded. • Affected: OpenPLC v3 deployed worldwide in critical manufacturing, energy, transportation, and water/wastewater systems • Vendor: Autonomy Logic (US-based)

TRC analysis reveals CVE-2026-88020 XSS vulnerability in OpenPLC Runtime v3 enables session hijacking and operator privilege escalation in industrial control systems. Attackers can pivot across OT networks through unencrypted east-west traffic flows. Runtime segmentation helps contain post-compromise lateral movement in industrial environments. #ICS #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/openplc-runtime-v3-cve-2026-88020-xss-vulnerability