SecurityPrimary source

OpenPLC Runtime v3

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy...

What happened

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions of OpenPLC Runtime v3 are affected: OpenPLC 3 (CVE-2026-88020) CVSS Vendor Equipment Vulnerabilities v3 6.1 Autonomy...

Why it matters

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. CISA Cybersecurity AdvisoriesPrimary source · Supports · EN · 100%
    OpenPLC Runtime v3

Claims

  • OpenPLC Runtime v3 Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust98
Independent corroboration51
Primary evidence100
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude96
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency86
Ranking · formula rank-1.0.0
Confidence factor0.9235
Freshness factor0.9556
Breaking bonus0
OpenPLC Runtime v3 | IntelCap