CVE-2026-88020: Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3
Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Autonomy Logic OpenPLCto a version that resolves this vulnerability.Fixed in v4
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack vector is network-based and requires no privileges, but it requires user interaction. An attacker would need to cause a user to interact with a crafted request containing a malicious query-string parameter.
Which component is affected?
The issue affects the web interface in Autonomy Logic OpenPLC Runtime 3 when it routes a program using an unencoded query-string parameter.
What is the likely impact if exploitation succeeds?
The provided severity vector indicates low confidentiality and integrity impact, with no availability impact. The scope is changed, meaning the impact can extend beyond the vulnerable component's authorization boundary.