CVE-2026-81823

Summary

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.

Affected Software

VendorProductVersion RangeStatus
AVEVAPipeline Integrity Monitor0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513)affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

Workarounds

AVEVA recommends the following general defensive measures:

  • Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
  • Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
  • Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References