Description
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated user to perform read operations that are reserved for authorized PIMBoards users, leading to exposure of sensitive project information. This is a missing authorization flaw (CWE‑862) that permits information disclosure without requiring any credentials.

Affected Systems

The affected software is AVEVA Pipeline Integrity Monitor, all versions prior to 2025 SP1 P2. The issue also applies to PIMBoards project files created with older versions. The recommended fix is to upgrade to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or later and migrate legacy project files.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability is of moderate severity and can be exploited remotely without authentication against the PIMBoards API. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers could read confidential pipeline data from project files if network access is not limited, so mitigation is important.

Generated by OpenCVE AI on September 8, 2026 at 18:36 UTC.

Remediation

Vendor Solution

AVEVA Pipeline Simulation media delivers AVEVA Pipeline Integrity Monitor: * All affected versions can be fixed by upgrading to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher: https://softwaresupportsp.aveva.com/en-US/downloads/products/details/021a26a7-200f-44eb-8cc9-cd57b7e349aa


Vendor Workaround

AVEVA recommends the following general defensive measures: * Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections. * Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access. * Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.


OpenCVE Recommended Actions

  • Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher security update
  • Migrate all existing PIMBoards project files to the updated version
  • Require all PIMBoards users to change their passwords
  • Restrict network access to the PIMBoards API using firewall controls so that only trusted client systems can connect
  • Apply strong ACLs to folders storing project files to limit read access to trusted users
  • Maintain a trusted chain of custody for project files during creation, modification, distribution, backup, and use

Generated by OpenCVE AI on September 8, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 14:45:00 +0000


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aveva
Aveva pipeline Integrity Monitor
Vendors & Products Aveva
Aveva pipeline Integrity Monitor

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Title AVEVA Pipeline Integrity Monitor Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aveva Pipeline Integrity Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T18:55:38.510Z

Reserved: 2026-08-27T13:26:11.856Z

Link: CVE-2026-81823

cve-icon Vulnrichment

Updated: 2026-09-08T18:28:11.479Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:20:57.733

Modified: 2026-09-14T19:17:49.780

Link: CVE-2026-81823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:25Z

Weaknesses