Pipeline operators and integrators using AVEVA Pipeline Integrity Monitor should identify PIMBoards deployments, upgrade to the 2025 SP1 P2 security release or later, and plan carefully for a one-way project-file migration.

Key takeaways

  • AVEVA bulletin AVEVA-2026-006, published September 8, 2026, covers four vulnerabilities in the PIMBoards component of Pipeline Integrity Monitor 2025 SP1 P1 build 7.1.9580.8513 and earlier.
  • Two high-severity findings could expose sensitive data or enable recovery of weakly protected PIMBoards application passwords when an attacker has read access to project files.
  • A separate unauthenticated API authorization issue can disclose information through certain read-only API methods; AVEVA states that write operations are not affected.
  • AVEVA directs affected customers to upgrade to Pipeline Integrity Monitor 2025 SP1 P2 or later, migrate older project files, restrict project-file access, and require PIMBoards users to change passwords.
  • Project-file migration to the fixed release is one-way, so teams should validate backups, rollback plans, access controls, and maintenance windows before making the production change.

Bulletin covers PIMBoards in Pipeline Integrity Monitor

AVEVA on September 8 published security bulletin AVEVA-2026-006, rating the issue set High. The bulletin applies to the PIMBoards component of AVEVA Pipeline Integrity Monitor 2025 SP1 P1, build 7.1.9580.8513, and all earlier versions. PIMBoards is the dashboard element used with AVEVA pipeline-simulation applications for visualization and display configuration. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

paragraphs?

Four CVEs describe different exposure paths

The bulletin assigns CVE-2026-81821 to a hardcoded encryption key. AVEVA says an actor with read access to PIMBoards project files could decrypt and view sensitive information. CVE-2026-81822 concerns use of MD5 password hashing; with the same level of project-file access, an attacker could attempt to recover weakly protected application-native passwords and potentially gain PIMBoards administrator access. Both issues carry CVSS v4.0 scores of 8.3. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

CVE-2026-81823 is a missing-authorization issue affecting a subset of GET API methods. It is scored 6.9 under CVSS v4.0 and could allow an unauthenticated party to perform read operations intended for PIMBoards users. AVEVA specifically says write operations are not affected. The fourth issue, CVE-2026-81824, is a reflected cross-site scripting flaw scored 6.3; successful exploitation requires a PIMBoards user to follow a malicious link, after which arbitrary JavaScript could run in that user’s browser session. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

Upgrade requires a project-file migration plan

AVEVA says all affected versions can be remediated by upgrading to Pipeline Integrity Monitor 2025 SP1 P2 or later. The vendor also instructs customers to migrate older PIMBoards project files and require PIMBoards users to change their passwords. This is not simply a binary update: AVEVA states that the project-file migration is one-way because the release changes the password-hashing approach and uses end-user-managed encryption keys. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

For operations teams, that one-way condition makes pre-change validation important. Inventory production, standby, engineering-workstation, test and archived project files; determine which files need to remain readable in legacy environments; and test the upgrade and migration process against representative nonproduction copies. Teams should also confirm that backup and recovery processes preserve an appropriate, access-controlled legacy copy without reintroducing insecure project-file handling.

Immediate controls should focus on files and API reachability

The two 8.3-rated issues depend on read access to project files, making file-share permissions, local administrator access, backup repositories and transient copies central to the exposure review. AVEVA recommends stricter read-access controls for project files that cannot be migrated, along with a trusted chain of custody during file creation, modification, distribution, backup and use. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

For the API authorization issue, AVEVA recommends host-based or network firewall controls on nodes hosting the PIMBoards API so only trusted client systems can connect. This should be treated as a compensating control during the upgrade window rather than a substitute for remediation. NIST’s OT security guidance likewise describes segmentation, mapped data flows and permit-by-exception firewall rules as components of a defense-in-depth architecture. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

What integrators and asset owners should do next

Start by confirming whether PIMBoards is installed and whether the affected release or an earlier one is in use. Then identify all instances that can reach PIMBoards API nodes, review ACLs on active and archived project-file locations, and schedule the vendor update within the site’s operational change-control process. Because passwords may have been stored using the affected MD5-based scheme in older project files, execute AVEVA’s password-change instruction after migration and coordinate credential updates with operators and support personnel. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))

Procurement and engineering teams should record the fixed target version—Pipeline Integrity Monitor 2025 SP1 P2 or later—in asset and maintenance records, while retaining the AVEVA bulletin and migration results as evidence for vulnerability-management closure. The bulletin does not describe an affected hardware product; the response is a software update, project-data migration and access-control exercise. ([aveva.com](https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdf))