Beckhoff TwinCAT 3 HMI Server Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in Beckhoff TwinCAT 3 HMI Server components prior to version 14.4.267. This issue allows authenticated administrators to inject arbitrary content into a custom CSS field. The injected content is persisted on the device and subsequently rendered on the login and error pages. Exploitation of this vulnerability requires malicious intent, as it involves the misuse of administrative privileges.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected content is executed in the context of the user's browser.

Remediation

Users are advised to update to a recent version of the affected components.

Added: Jan 20, 2026, 9:24 AM
Updated: Jan 20, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
2.8
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.