CVE-2026-5387: AVEVA Pipeline Simulation Missing Authorization
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5387?
CVE-2026-5387 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-5387?
To mitigate CVE-2026-5387, ensure that access controls are properly implemented and that unauthorized users are not allowed to perform restricted operations.
What are the potential impacts of CVE-2026-5387?
Exploiting CVE-2026-5387 could allow unauthorized users to perform actions intended for high-level roles, leading to system compromise.
Who is affected by CVE-2026-5387?
CVE-2026-5387 affects users of AVEVA Pipeline Simulation software who do not have proper authorization mechanisms in place.
Is CVE-2026-5387 actively being exploited?
There are currently no public reports confirming active exploitation of CVE-2026-5387, but it remains a serious concern.