CVE-2026-88020

6.1

Autonomy Logic · OpenPLC Runtime

Autonomy Logic OpenPLC 3 contains a cross-site scripting vulnerability caused by improper neutralization of input in the web interface query string parameters.

Executive summary

Autonomy Logic OpenPLC 3 is vulnerable to cross-site scripting due to unvalidated input in its web interface, which may allow attackers to execute malicious scripts in a user's browser.

Vulnerability

This vulnerability is a cross-site scripting (CWE-79) flaw where the web interface fails to sanitize query string parameters. The attack vector is network-based and requires no authentication, though it does require user interaction.

Business impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the web interface, potentially leading to session hijacking, unauthorized actions performed on behalf of an administrator, or the theft of sensitive session cookies. While the CVSS score of 6.1 indicates a medium severity, the impact on industrial control environments can be significant due to the potential for disrupting critical monitoring and operational oversight.

Remediation

Immediate Action: Upgrade to OpenPLC version 4, as version 3 is end-of-life and will not receive further security patches.

Proactive Monitoring: Monitor web server access logs for unusual query string patterns or suspicious URL parameters that may indicate injection attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious input and block XSS attack patterns targeting the web interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The reliance on an end-of-life product introduces unacceptable risk to operational technology environments. Organizations should prioritize the migration to OpenPLC version 4 immediately to ensure ongoing support and security patching, as the current version 3 remains permanently vulnerable to this and potentially other undiscovered flaws.

History

  1. Analyst report written

Sources

Originally found and disclosed by Rajivarnan R. reported this vulnerability to CISA., Shirshak of Secnora reported this vulnerability to CISA., per the CVE Program record.