CVE-2026-81824
6.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H
Summary
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AVEVA | Pipeline Integrity Monitor | 0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513) | affected |
Weaknesses
- CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Workarounds
AVEVA recommends the following general defensive measures:
- Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
- Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
- Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.