ZeroHour

CVE-2026-81824

niche

Cross-Site Scripting (XSS) in AVEVA Pipeline Integrity Monitor PIMBoards

CVSS 4.0
6.3 medium
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-81824 is a cross-site scripting flaw (CWE-79) in PIMBoards, the dashboard/boards component of AVEVA Pipeline Integrity Monitor. An attacker must socially engineer an authenticated PIMBoards user into clicking a malicious link, which then causes attacker-controlled JavaScript to run inside that user's browser session. Successful exploitation would let the attacker act within the victim's session, and the CVSS 4.0 vector's high integrity and availability impacts on subsequent systems indicate the injected script could take actions affecting connected or downstream systems. Only users of the PIMBoards component of Pipeline Integrity Monitor who follow a malicious link are affected; unexposed or unattended deployments face little risk. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.3% (22nd percentile), so exploitation is not currently observed.

What to do: Monitor the CISA ICS advisory and AVEVA product notifications for the affected version list and patched release, then upgrade Pipeline Integrity Monitor/PIMBoards when a fix is published. Until patched, restrict web access to the PIMBoards interface to trusted users and networks and caution users against clicking unsolicited links. Because no exploit or in-the-wild activity is known, there is no urgent compromise-hunting action, but log review of PIMBoards web sessions is reasonable for high-value pipeline environments.

Affected
AVEVA Pipeline Integrity Monitor - PIMBoards component
Estimated exposure
nicheunknown (no public install counts; likely hundreds to low thousands of deployments at pipeline operators) — Pipeline Integrity Monitor is specialized industrial software assigned by CISA ICS-CERT, implying a limited install base among pipeline operators rather than mass-market deployment, and no public exposure scan or install-count data is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

AVEVA Pipeline Integrity Monitor

CISA advisory details four flaws in AVEVA Pipeline Integrity Monitor <=2025_SP1_P1, allowing information disclosure, weak-hash admin elevation, and cross-site scripting.

CISA published ICSA-26-253-01 covering AVEVA Pipeline Integrity Monitor versions <=2025_SP1_P1_build_7.1.9580.8513. CVE-2026-81821 (hard-coded cryptographic key, CWE-321) lets a user with read access decrypt PIMBoards project files, and CVE-2026-81822 (CWE-327) allows brute-forcing weak password hashes to elevate to PIMBoards administrator; both score 8.4 HIGH (CVSS v3.1). CVE-2026-81823 (CWE-862) permits unauthenticated read operations, and CVE-2026-81824 (CWE-79) enables arbitrary JavaScript execution via socially engineered links. CISA reports no known public exploitation and recommends limiting network exposure of control system devices.