CVE-2026-88020

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-22: 309-22
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew

    CVE-2026-88020 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the p… https://www.cve.org/CVERecord?id=CVE-2026-88020

    00000842
    58.1K followersView on X
  • NewsTongue@NewsTongueX

    🔴 OpenPLC Runtime v3 flaw lets attackers hijack operator sessions, control industrial systems A cross-site scripting vulnerability (CVE-2026-88020) in OpenPLC Runtime v3 allows attackers to steal session cookies and issue commands as an operator, gaining control over programmable logic controllers and their connected physical processes. The vulnerability stems from improper input neutralization in the web interface's query string routing, leaving it unencoded. • Affected: OpenPLC v3 deployed worldwide in critical manufacturing, energy, transportation, and water/wastewater systems • Vendor: Autonomy Logic (US-based)

    0000027
    901 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis reveals CVE-2026-88020 XSS vulnerability in OpenPLC Runtime v3 enables session hijacking and operator privilege escalation in industrial control systems. Attackers can pivot across OT networks through unencrypted east-west traffic flows. Runtime segmentation helps contain post-compromise lateral movement in industrial environments. #ICS #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/openplc-runtime-v3-cve-2026-88020-xss-vulnerability

    0000040
    2.0K followersView on X

Explore more