CVE-2026-81824

Summary

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

Affected Software

VendorProductVersion RangeStatus
AVEVAPipeline Integrity Monitor0 <= Versions 2025 SP1 P1 (build 7.1.9580.8513)affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

Workarounds

AVEVA recommends the following general defensive measures:

  • Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections.
  • Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access.
  • Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References