CVE-2026-1495: Insertion of Sensitive Information into Log File vulnerability in AVEVA PI to CONNECT Agent
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1495?
CVE-2026-1495 is considered a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2026-1495?
To remediate CVE-2026-1495, it is recommended to restrict access to Event Log Reader privileges and review logging practices.
What could happen if CVE-2026-1495 is exploited?
If CVE-2026-1495 is exploited, an attacker could gain access to sensitive proxy information including URLs and credentials.
Who is affected by CVE-2026-1495?
CVE-2026-1495 affects users of the AVEVA PI to CONNECT Agent who have Event Log Reader permissions.
Is there a known workaround for CVE-2026-1495?
Currently, the most effective workaround for CVE-2026-1495 is to limit the use of Event Log Reader privileges and implement logging safeguards.