Vulnerability record

CVE-2026-88020

Severity: ElevatedExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-88020 scored CVSS 5.3

    Basis: NIST National Vulnerability Database

Coverage

Severity: HighAction: Review

OpenPLC Runtime v3

References

  • github.com https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-09.json
  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09