CVE-2026-81823
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AVEVA | Pipeline Integrity Monitor | 0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513) | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
Workarounds
AVEVA recommends the following general defensive measures:
- Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
- Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
- Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.