{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openplc-runtime-v3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenPLC Runtime v3"],"_cs_severities":["medium"],"_cs_tags":["xss","ics","cve-2026-88020","critical-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Autonomy Logic"],"content_html":"\u003cp\u003eOpenPLC Runtime v3, developed by Autonomy Logic, contains a vulnerability identified as CVE-2026-88020. The flaw stems from improper neutralization of input within the product's web interface, specifically when the application routes programs based on unencoded query string parameters. This cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts into the web interface.\u003c/p\u003e\n\u003cp\u003eIf a logged-in operator visits a crafted link or navigates to a compromised page, the attacker can hijack active session cookies. By gaining control of an operator's session, an attacker can issue state-changing requests, potentially manipulating the programmable logic controller (PLC) and disrupting the physical industrial processes it manages. OpenPLC Runtime v3 has reached end-of-life status and will not receive security patches; the vendor advises all users to upgrade to OpenPLC v4 to remediate this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects critical infrastructure sectors including energy, water, manufacturing, and transportation systems globally. Successful exploitation allows for session hijacking, enabling unauthorized control over physical industrial processes. If exploited, an attacker could potentially override safety logic or disrupt operational technology (OT) services, leading to physical damage or process outages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately migrate from OpenPLC v3 to OpenPLC v4, as v3 is end-of-life and will not be patched for CVE-2026-88020.\u003c/li\u003e\n\u003cli\u003eIsolate all OpenPLC web interfaces from public internet access by placing them behind firewalls or utilizing VPNs for remote management.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to ensure control system devices are not reachable from business or guest networks.\u003c/li\u003e\n\u003cli\u003eConduct an audit of existing industrial control system (ICS) exposure to identify and block unauthorized access to web-based management consoles.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T17:46:58Z","date_published":"2026-09-22T17:46:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openplc-runtime-xss/","summary":"OpenPLC Runtime v3 contains a cross-site scripting vulnerability that allows attackers to hijack operator session cookies and issue unauthorized commands to industrial control processes.","title":"Stored and Reflected XSS Vulnerability in OpenPLC Runtime v3","url":"https://feed.craftedsignal.io/briefs/2026-09-openplc-runtime-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenPLC Runtime V3","version":"https://jsonfeed.org/version/1.1"}