Status: UPDATED
| Advisory ID: CVE-2026-5387
Key Details
| CVE | CVE-2026-5387 |
| CVSS Score / Version | 9.3 (Critical) / CVSS v4.0 |
| Updated | 2026-06-17 |
| Affected products | AVEVA Pipeline Simulation 2025 |
| Classified as | CWE-862 (Missing Authorization) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.
What to Do
Monitor AVEVA's web page for any future patch releases.
References