Back to Feed
VulnerabilitiesSep 10, 2026

AVEVA Pipeline Integrity Monitor

AVEVA Pipeline Integrity Monitor has multiple critical vulnerabilities allowing data disclosure and code execution.

Summary

AVEVA has released a security update addressing four critical vulnerabilities in its Pipeline Integrity Monitor software. These flaws, ranging from hard-coded cryptographic keys to cross-site scripting, could allow attackers to disclose sensitive information, brute-force passwords, or execute arbitrary code. The affected versions are <=2025_SP1_P1_build_7.1.9580.8513, and AVEVA recommends applying the 2025 SP1 P2 Security Update and migrating project files.

Full text

ICS Advisory AVEVA Pipeline Integrity Monitor Release DateSeptember 10, 2026 Alert CodeICSA-26-253-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded Cryptographic Key, Use of a Broken or Risky Cryptographic Algorithm, Missing Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2026-81821 The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor:AVEVA Product Version:AVEVA AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status:known_affected Remediations Vendor fixAVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Vendor fixImportant: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys. MitigationFor more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N 4.0 8.3 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-81822 The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users' app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor:AVEVA Product Version:AVEVA AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status:known_affected Remediations Vendor fixAVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Vendor fixImportant: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys. MitigationFor more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf Relevant CWE: CWE-327 Use of a Broken or Risky Cryptographic Algorithm Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N 4.0 8.3 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-81823 The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor:AVEVA Product Version:AVEVA AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status:known_affected Remediations Vendor fixAVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Vendor fixImportant: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys. MitigationFor more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-81824 The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link. View CVE Details Affected Products AVEVA Pipeline Integrity Monitor Vendor:AVEVA Product Version:AVEVA AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513 Product Status:known_affected Remediations Vendor fixAVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit: Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files. For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files. Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords. Vendor fixImportant: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys. MitigationFor more information, see AVEVA security bulletin AVEVA-2026-006. https://www.aveva.com/content/dam/aveva/documents/support/

Indicators of Compromise

  • cve — CVE-2026-81821
  • cve — CVE-2026-81822
  • cve — CVE-2026-81823
  • cve — CVE-2026-81824
  • url — https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf

Entities

Pipeline Integrity Monitor (product)AVEVA (vendor)Industrial Control System (technology)