PT-2026-33078 · Aveva · Aveva Pipeline Simulation

Published

2026-04-15

·

Updated

2026-04-17

·

CVE-2026-5387

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AVEVA Pipeline Simulation (affected versions not specified)
Description An issue exists where unauthenticated network access allows a remote attacker to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles. This leads to privilege escalation, enabling the modification of simulation parameters, training configuration, and training records.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5387

Affected Products

Aveva Pipeline Simulation