Description
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting allowing arbitrary JavaScript execution in a user's browser session
Action: Immediate Patch
AI Analysis

Impact

This vulnerability, a client‑side XSS (CWE-79) attack, permits arbitrary JavaScript execution within the web browser of a PIMBoards user who clicks a malicious link. This can be leveraged to steal credentials, deface content or launch additional attacks against that user’s session.

Affected Systems

AVEVA Pipeline Integrity Monitor is affected. All versions prior to 2025 SP1 P2 are vulnerable; the vendor recommends upgrading to 2025 SP1 P2 or newer. Project files from older versions, especially those that cannot be migrated, pose a risk if left unchecked.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS is not reported, so exploitation likelihood is unknown. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires a user to click a malicious link, it is a social‑engineering attack vector that could deliver malware or capture credentials, potentially enabling lateral movement for an attacker who gains access to an administrative account.

Generated by OpenCVE AI on September 8, 2026 at 19:04 UTC.

Remediation

Vendor Solution

AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: * Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. * For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. * Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.


Vendor Workaround

AVEVA recommends the following general defensive measures: * Restrict Network Access: Implement host-based and/or network firewall controls on all nodes hosting the PIMBoards API to ensure that only trusted client systems are permitted to establish connections. * Apply strong Access Control Lists to all folders storing project files to ensure only trusted users have read-access. * Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use.


OpenCVE Recommended Actions

  • Upgrade AVEVA Pipeline Integrity Monitor to version 2025 SP1 P2 or later.
  • Migrate all existing project files to the new format; for files that cannot be migrated, restrict read access and assess the risk of password leakage.
  • Mandate password changes for all PIMBoards users.
  • Restrict network access to the PIMBoards API so that only trusted hosts can connect.
  • Apply strict access control lists to folders containing project files.
  • Maintain a trusted chain‑of‑custody for project files through creation, modification, and backup.

Generated by OpenCVE AI on September 8, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:45:00 +0000


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Aveva
Aveva pipeline Integrity Monitor
Vendors & Products Aveva
Aveva pipeline Integrity Monitor

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Title AVEVA Pipeline Integrity Monitor cross-site scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H'}


Subscriptions

Aveva Pipeline Integrity Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T14:30:02.185Z

Reserved: 2026-08-27T13:26:12.638Z

Link: CVE-2026-81824

cve-icon Vulnrichment

Updated: 2026-09-08T18:27:27.759Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:20:57.880

Modified: 2026-09-11T15:17:05.763

Link: CVE-2026-81824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:27Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')