Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
Quick answers
What is CVE-2026-81824?
Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
How severe is CVE-2026-81824?
high, CVSS 8.4
Is CVE-2026-81824 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-81824 be mitigated?
Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
CVSS
8.4
Vendor
AVEVA
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
AVEVA Pipeline Integrity Monitor
Mitigation
Organizations should apply the AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate affected project files. For files that cannot be migrated, evaluate the risk of password leakage and implement stricter read access controls. Require PIMBoards users to change their passwords after migration. Migration is one-way due to changes in password hashing algorithms and encryption keys.
CISA and AVEVA have disclosed four vulnerabilities in AVEVA Pipeline Integrity Monitor that could allow an attacker with read access to PIMBoards project files to decrypt sensitive information, brute-force user passwords through weak cryptographic hashes, or execute cross-site scripting attacks. The flaws affect all versions up to and including build 7.1.9580.8513. AVEVA has released a security update (2025 SP1 P2) and advises migration of affected project files.