news.mlab.sh
Back to the feed
vulnerability

OpenPLC Runtime v3

Critical
Summary

A critical vulnerability (CVE-2026-88020) exists in OpenPLC Runtime v3, allowing attackers to hijack session cookies and control programmable logic controllers. This could lead to significant disruption of critical infrastructure, including manufacturing, energy, transportation, and water systems. The vendor recommends upgrading to OpenPLC v4, and CISA advises implementing network segmentation and secure remote access practices.

A critical vulnerability (CVE-2026-88020) exists in OpenPLC Runtime v3, allowing attackers to hijack session cookies and control programmable logic controllers. This could lead to significant disruption of critical infrastructure, including manufacturing, energy, transportation, and water systems. The vendor recommends upgrading to OpenPLC v4, as OpenPLC v3 is end-of-life and no longer receiving security updates. The vulnerability stems from improper neutralization of input during web page generation, specifically when the web interface attempts to route the program based on a query string parameter without encoding.

Affected Products include OpenPLC Runtime v3 and Autonomy Logic OpenPLC: 3.

Countries/Areas Deployed: Worldwide. Company Headquarters Location: United States.

Remediations: Vendor fix – Autonomy Logic recommends users upgrade to OpenPLC v4. CISA recommends minimizing network exposure for all control system devices, isolating them from business networks, and using secure remote access methods like VPNs (recognizing VPN vulnerabilities).

Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

Read the full article at CISA Advisories