CVE-2026-81821 Details
Description
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
A vulnerability exists in the PIMBoards component of AVEVA Pipeline Integrity Monitor, specifically in versions through 2025 SP1 P1 (build 7.1.9580.8513). This vulnerability arises from a hardcoded encryption key, which, if exploited, could enable an individual with read access to PIMBoards project files to decrypt and access sensitive information. The issue is compounded by the fact that affected project files may contain passwords hashed with MD5, a broken cryptographic algorithm, further increasing the risk of exploitation.
Users are advised to upgrade to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher and migrate old project files. For files that cannot be migrated, implement stricter read access controls. Additionally, PIMBoards users should be required to change their passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json | [email protected] | AdvisoryBundleRemedy |
| https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AVEVA Pipeline Integrity Monitor | <= 2025_SP1_P1_build_7.1.9580.8513 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | [email protected] |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion