OpenPLC Runtime v3
Summary
OpenPLC Runtime v3 versions are affected by CVE-2026-88020, a cross-site scripting vulnerability. Successful exploitation could allow an attacker to hijack session cookies and issue state-changing requests, enabling control of the programmable logic controller and its associated physical processes.
IFF Assessment
The vulnerability allows attackers to hijack sessions and control industrial processes, posing a direct threat to critical infrastructure.
Severity
The CVSS score of 6.1 (MEDIUM) reflects the attack vector (network accessible), privileges required (none), and user interaction (none required for session hijacking), with a significant impact on integrity and availability for industrial control systems.
Defender Context
This vulnerability in OpenPLC Runtime v3 highlights the persistent risks associated with legacy industrial control systems that are no longer receiving security updates. Defenders must prioritize inventorying and monitoring such systems, especially those controlling critical infrastructure, and develop mitigation strategies as vendor fixes are unavailable.