Skip to content
Threat Feed
medium advisory

Stored and Reflected XSS Vulnerability in OpenPLC Runtime v3

OpenPLC Runtime v3 contains a cross-site scripting vulnerability that allows attackers to hijack operator session cookies and issue unauthorized commands to industrial control processes.

OpenPLC Runtime v3, developed by Autonomy Logic, contains a vulnerability identified as CVE-2026-88020. The flaw stems from improper neutralization of input within the product's web interface, specifically when the application routes programs based on unencoded query string parameters. This cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts into the web interface.

If a logged-in operator visits a crafted link or navigates to a compromised page, the attacker can hijack active session cookies. By gaining control of an operator's session, an attacker can issue state-changing requests, potentially manipulating the programmable logic controller (PLC) and disrupting the physical industrial processes it manages. OpenPLC Runtime v3 has reached end-of-life status and will not receive security patches; the vendor advises all users to upgrade to OpenPLC v4 to remediate this issue.

Impact

The vulnerability affects critical infrastructure sectors including energy, water, manufacturing, and transportation systems globally. Successful exploitation allows for session hijacking, enabling unauthorized control over physical industrial processes. If exploited, an attacker could potentially override safety logic or disrupt operational technology (OT) services, leading to physical damage or process outages.

Recommendation

Prioritized actions for security operations and IT teams:

  • Immediately migrate from OpenPLC v3 to OpenPLC v4, as v3 is end-of-life and will not be patched for CVE-2026-88020.
  • Isolate all OpenPLC web interfaces from public internet access by placing them behind firewalls or utilizing VPNs for remote management.
  • Implement strict network segmentation to ensure control system devices are not reachable from business or guest networks.
  • Conduct an audit of existing industrial control system (ICS) exposure to identify and block unauthorized access to web-based management consoles.

Immediate actions

Upgrade all OpenPLC Runtime v3 instances to OpenPLC v4

IT Operations 72h

Mitigations

Isolate OpenPLC Runtime v3 web interfaces from the internet

immediate IT Operations

CVE-2026-88020