CVE-2026-81824: AVEVA Pipeline Integrity Monitor cross-site scripting
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVEVA Pipeline Integrity Monitorto a version that resolves this vulnerability.Fixed in 2025 SP1 P2 - Configuration
Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords after upgrading, due to password hashing algorithm changes in the one-way migration to 2025 SP1 P2.
PIMBoards passwords = changed - Compensating control
For PIMBoards project files that cannot be migrated (e.g., backups or transient copies), evaluate risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to socially engineer a PIMBoards user into clicking a malicious link. No attacker authentication or privileges are required.
Who is exposed to the impact?
PIMBoards users who open an attacker-controlled malicious link in their browser are exposed. Successful exploitation runs arbitrary JavaScript in that user's browser session.