VYPR
advisoryPublished Sep 22, 2026· 1 source

CISA Warns of Cross-Site Scripting Vulnerability in OpenPLC Runtime v3

CISA has issued an advisory for OpenPLC Runtime v3, detailing CVE-2026-88020, a medium-severity cross-site scripting vulnerability that could allow attackers to control industrial processes.

CISA has released an advisory detailing a cross-site scripting (XSS) vulnerability, identified as CVE-2026-88020, affecting OpenPLC Runtime version 3. This vulnerability, rated as medium severity with a CVSS base score of 6.1, poses a significant risk to critical infrastructure sectors including critical manufacturing, energy, transportation systems, and water and wastewater systems worldwide.

The vulnerability stems from an improper neutralization of input during web page generation within the product's web interface. Specifically, when the interface attempts to route program execution based on a query string parameter without proper encoding, it becomes susceptible to XSS attacks. Successful exploitation could allow an unauthenticated attacker to inject malicious scripts into the web interface.

Exploitation of this flaw could lead to severe consequences, including the hijacking of operator session cookies. This would enable an attacker to impersonate legitimate users, issue state-changing requests, and ultimately gain control over the programmable logic controller (PLC). Consequently, an attacker could manipulate the physical processes managed by the PLC, potentially causing operational disruptions or damage.

Autonomy Logic, the vendor behind OpenPLC, has declared OpenPLC Runtime v3 to be end-of-life. This means the product is no longer receiving security patches, bug fixes, or any form of security updates. The vendor strongly recommends that all users upgrade to the latest version, OpenPLC v4, to mitigate this and any other potential future vulnerabilities.

While CISA has not reported any known public exploitation specifically targeting this vulnerability at this time, the potential impact necessitates immediate attention. CISA strongly advises organizations to implement defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet, and locating control system networks behind firewalls, isolating them from business networks.

For remote access, CISA recommends using secure methods such as Virtual Private Networks (VPNs), while also emphasizing that VPNs themselves must be kept updated and are only as secure as the connected devices. Organizations are encouraged to perform thorough impact analyses and risk assessments before deploying any defensive measures.

CISA also provides broader guidance on industrial control systems (ICS) cybersecurity, recommending practices such as defense-in-depth strategies and targeted cyber intrusion detection and mitigation. The agency also reminds users to be vigilant against social engineering attacks, such as phishing, by not clicking on suspicious links or opening unsolicited attachments.

The vulnerability was reported to CISA by Rajivarnan R. and Shirshak of Secnora. The advisory serves as a critical alert for operators of industrial control systems to address the security posture of their OpenPLC Runtime v3 deployments and to plan for an upgrade to a supported version.

Synthesized by Vypr AI