CVE-2026-81824 PUBLISHED

AVEVA Pipeline Integrity Monitor cross-site scripting

Assigner: icscert
Reserved: 27.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H
CVSS Score: 6.3

Product Status

Vendor AVEVA
Product Pipeline Integrity Monitor
Versions Default: unaffected
  • affected from 0 to Versions 2025 SP1 P1 (build 7.1.9580.8513) (incl.)

Workarounds

AVEVA recommends the following general defensive measures: * Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections. * Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access. * Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.

Solutions

AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor: * All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher:

https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa

Credits

  • Adham Khairy Ramadan discovered and reported this vulnerability to AVEVA through a private HackerOne bug bounty program. finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE