AI analysis
CVE-2026-81823 is a missing-authorization flaw (CWE-862) in AVEVA Pipeline Integrity Monitor that allows an unauthenticated remote attacker to invoke read operations intended only for PIMBoards users. It is triggered by sending unauthenticated network requests to the affected read-only functionality, with no special conditions or user interaction required (CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:N/UI:N). A successful exploit yields information disclosure of data readable through PIMBoards; write operations are explicitly not impacted, so attackers cannot modify data through this flaw. At-risk deployments are installations of AVEVA Pipeline Integrity Monitor where the PIMBoards interface is reachable by untrusted network users, a profile typical of pipeline operators' OT environments. No exploitation is currently known: there is no public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates a 0.3% probability of exploitation in the next 30 days (24th percentile).
What to do: Consult the AVEVA and CISA ICS advisories for the exact affected version range and update to the patched release they specify. Until patched, restrict network access to the PIMBoards interface using firewall rules or ACLs so it is reachable only from trusted operator networks, since the flaw requires only network reachability and no credentials. Review logs for unauthenticated read activity against PIMBoards endpoints to check whether data has already been exposed; note the issue is disclosure-only and does not affect write operations.
Affected
| AVEVA (Schneider Electric) Pipeline Integrity Monitor | — |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.