🔐 CVE Alert

CVE-2026-88020

MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

CWE CWE-79
Vendor autonomy logic
Product openplc runtime
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for autonomy logic openplc runtime

Be the first to know when new medium vulnerabilities affecting autonomy logic openplc runtime are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Autonomy Logic / OpenPLC Runtime
3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-09.json

Credits

Rajivarnan R. reported this vulnerability to CISA. Shirshak of Secnora reported this vulnerability to CISA.