CVE-2026-81824 Details
Description
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
A reflective cross-site scripting vulnerability has been identified in the PIMBoards component of AVEVA Pipeline Integrity Monitor. This issue affects versions through 2025 SP1 P1 (build 7.1.9580.8513). If exploited, the vulnerability could allow an attacker to execute arbitrary JavaScript in the browser session of a PIMBoards user who is tricked into clicking a malicious link.
Users are advised to upgrade to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 or higher. For more information, see the AVEVA security bulletin AVEVA-2026-006.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json | [email protected] | AdvisoryBundleRemedy |
| https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AVEVA Pipeline Integrity Monitor | <= 2025_SP1_P1_build_7.1.9580.8513 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | [email protected] |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion