Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor
AVEVA Pipeline Integrity Monitor versions through 2025_SP1_P1_build_7.1.9580.8513 contain multiple vulnerabilities including hard-coded keys and improper authorization, facilitating information disclosure, credential brute-forcing, and XSS-based code execution.
CVE search metadata
CVE search record: CVE-2026-81821. Severity: high. CVSS: 8.4. EPSS: 0.14%. KEV: no. Product: Pipeline Integrity Monitor (<= 2025_SP1_P1_build_7.1.9580.8513). Brief: Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aveva-pim-vulnerabilities/
CVE search record: CVE-2026-81822. Severity: high. CVSS: 8.4. EPSS: 0.11%. KEV: no. Product: Pipeline Integrity Monitor (<= 2025_SP1_P1_build_7.1.9580.8513). Brief: Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aveva-pim-vulnerabilities/
CVE search record: CVE-2026-81823. Severity: medium. CVSS: 5.3. EPSS: 0.31%. KEV: no. Product: Pipeline Integrity Monitor (<= 2025_SP1_P1_build_7.1.9580.8513). Brief: Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aveva-pim-vulnerabilities/
CVE search record: CVE-2026-81824. Severity: medium. CVSS: 4.7. EPSS: 0.30%. KEV: no. Product: Pipeline Integrity Monitor (<= 2025_SP1_P1_build_7.1.9580.8513). Brief: Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aveva-pim-vulnerabilities/
AVEVA Pipeline Integrity Monitor (PIM) is affected by four vulnerabilities (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) impacting PIMBoards project files and user sessions. The vulnerabilities, discovered in versions up to 2025_SP1_P1_build_7.1.9580.8513, allow attackers with read access to project files to decrypt sensitive information or perform brute-force attacks against weak password hashes, potentially leading to administrative privilege escalation. Furthermore, missing authorization allows unauthorized unauthenticated read access to PIMBoards data. Finally, an XSS vulnerability enables arbitrary JavaScript execution within an authenticated user's browser session via social engineering. Given the use in critical infrastructure sectors, these vulnerabilities present a significant risk for data exfiltration and credential compromise.
Impact
Successful exploitation allows for unauthorized disclosure of sensitive industrial information, compromise of user credentials leading to administrative access within PIMBoards, and potential session hijacking or further malicious activity through arbitrary code execution in browser environments. These risks affect global deployments in the Critical Manufacturing sector.
Recommendation
- Apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update immediately and perform the required one-way migration of PIMBoards project files.
- For project files that cannot be migrated (e.g., backups or transient copies), implement strict file-system read access controls to mitigate the risk of unauthorized decryption.
- Enforce a mandatory password change for all PIMBoards users following the upgrade to 2025 SP1 P2, as the migration changes underlying password hashing algorithms.
- Review security bulletin AVEVA-2026-006 for full remediation details and architectural guidance.
Immediate actions
Upgrade to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 and migrate project files
Force password resets for all PIMBoards users
Mitigations
Restrict read access to PIMBoards project files (.pimboards or equivalent)
CVE-2026-81821, CVE-2026-81822