CVE-2026-81823: AVEVA Pipeline Integrity Monitor Missing Authorization
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2 - Operational
For PIMBoards project files that cannot be migrated (e.g., backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
- Operational
Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
No authentication, privileges, or user interaction are required. The issue is reachable over the network and can be exploited with low attack complexity.
What can an attacker do if they exploit it?
An attacker can perform read operations that are intended only for PIMBoards users, which may disclose information. The available information does not indicate any impact on write operations.
Is data modification or service disruption expected from this vulnerability?
No. The reported impact is limited to confidentiality; integrity and availability are not affected.