Weakness class in the advisory: CWE-79 (Source: CISA ICS advisory on OpenPLC Runtime v3 (reviewed September 28, 2026))
A cross-site scripting flaw in the web interface of OpenPLC Runtime v3 could let an attacker take over an operator's session and command a programmable logic controller (PLC). The vendor says no fix is coming, because v3 is end-of-life. A CISA ICS advisory carries Autonomy Logic's guidance to upgrade to OpenPLC v4. For organisations still running v3, this is a migration decision, not a patch cycle.
What the flaw allows
The advisory files the issue under CWE-79, the cross-site scripting category. The mechanism is narrow. The web interface uses a value in the URL's query string to decide which program to load, and it leaves that value unencoded.
CISA's assessment of the consequence is broad. A successful attack would let someone lift an operator's session cookies and then send requests that change system state under that operator's identity. In practice that means steering the controller and the physical processes attached to it. Rajivarnan R. and Shirshak of Secnora reported the issue to CISA.
Why end-of-life changes the decision
Autonomy Logic describes v3 as end-of-life, meaning it has stopped shipping fixes of any kind, security or otherwise. That leaves no remediation inside v3. The only vendor-recommended route is v4, so the spend shifts from applying an update to funding a move to a different major version.
On exploitation, the agency's statement is limited: it had not been told of attacks aimed specifically at this flaw. That describes what has been reported to CISA. It says nothing about what is happening inside any individual network, and a flaw with no vendor fix path stays open for as long as v3 stays in service.
Compensating controls CISA points to
With no patch available, exposure reduction carries the weight. CISA advises keeping control system devices off the internet. It also advises placing control networks and remote devices behind firewalls, separated from business networks. Where remote access is required, CISA suggests VPNs, with the caveat that VPNs may themselves have vulnerabilities and are only as secure as the devices connected through them.
The advisory also carries CISA's standard social-engineering guidance, including not clicking web links or opening attachments in unsolicited email. That guidance is relevant because the described attack works through an operator's authenticated web session.
One gap to close: the advisory text reviewed for this story does not enumerate the affected version numbers or a CVE identifier. Teams should confirm scope against the full advisory on cisa.gov before deciding which instances are in play.
Questions to put to your team
1. Do we run OpenPLC Runtime v3 anywhere, including test benches and pilot lines, and who owns each instance?
2. Is any v3 web interface reachable from the internet, or from the business network rather than an isolated control network?
3. What is the plan and date to move to v4, and what re-validation of existing control programs does it require?
4. Until then, which operators log in through the browser interface, and can those workstations receive email or browse the web?
5. What other end-of-life components sit in our control environment with no vendor patch path?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





