AllCyberNews

CVE-2026-88020

Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3

CVSS 5.3 medium · Autonomy Logic OpenPLC Runtime · published 2026-09-22

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Coverage 1 source

  1. 2026-09-22 CISA Cybersecurity Advisories medium OpenPLC Runtime v3

    A vulnerability in OpenPLC Runtime v3 could allow an attacker to hijack session cookies and control the programmable logic controller.

Also covered