CVE-2026-88020

Summary

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Affected Software

VendorProductVersion RangeStatus
Autonomy LogicOpenPLC Runtime3affected
Autonomy LogicOpenPLC Runtime4unaffected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

References