CVE-2026-81822: AVEVA Pipeline Integrity Monitor Use of a Broken or Risky Cryptographic Algorithm
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2 - Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2Patch AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update - Configuration
Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords for project files that cannot be migrated to AVEVA Pipeline Integrity Monitor 2025 SP1 P2.
PIMBoards passwords = change - Compensating control
For PIMBoards project files that cannot be migrated (e.g., backups or transient copies), evaluate risk of potential password leakage and implement stricter read access controls to protect these unsafe files.
Event History
Frequently Asked Questions
Who is exposed to this issue?
PIMBoards deployments are exposed where an attacker can obtain read access to PIMBoards project files. The affected credentials are PIMBoards users’ app-native passwords.
What does an attacker need to exploit it?
The attacker needs read access to PIMBoards project files and must computationally brute-force the weak password hashes. Successful recovery of credentials could permit elevation to a PIMBoards administrator user.
How can teams determine whether they may already be at risk?
Review who has read access to PIMBoards project files, including users, service accounts, shared storage, backups, and other locations where those files are accessible. Any unauthorized or overly broad read access creates the prerequisite described for exploitation.