← All Advisories

CVE-2026-5387

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-5387

Key Details

CVECVE-2026-5387
CVSS Score / Version9.3 (Critical) / CVSS v4.0
Updated2026-06-17
Affected productsAVEVA Pipeline Simulation 2025
Classified asCWE-862 (Missing Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
AVEVAPipeline Simulation 2025
SubsystemsGeneral OT
SectorsMultiple

What to Know

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.

What to Do

Monitor AVEVA's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5387
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-5387