logo

Critical 9.3 Flaw Lets Outsiders Hijack AVEVA Pipeline Simulations

ID: 3f4f36fc-aae5-52c2-bcca-8000bd31fe2c

STIX ID: report--3f4f36fc-aae5-52c2-bcca-8000bd31fe2c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-18

Date Updated: 2026-04-23

Author: Ddos

...
...

AVEVA published a critical advisory for AVEVA Pipeline Simulation (CVE-2026-5387) describing a Missing Authorization (CWE-862) flaw with CVSSv4.0 9.3 that could let unauthenticated attackers perform administrator-level operations and alter simulation parameters and training records; affected versions include 2025 SP1 (build 7.1.9497.6351) and earlier, and AVEVA advises upgrading to 2025 SP1 P01 (build 7.1.9580.8513) or later to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.