type: cve ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [cve, ics, ot, cryptography, energy] ยท confidence: medium ยท severity: high ยท affected_sectors: [global] ยท au_impact: false
The flaws comprise CVE-2026-81821, use of a hard-coded cryptographic key that allows anyone with read access to PIMBoards project files to decrypt and view sensitive information; CVE-2026-81822, use of a broken or risky cryptographic algorithm; CVE-2026-81823, missing authorization; and CVE-2026-81824, a cross-site scripting flaw โ chained, they allow information disclosure, hash brute-forcing or arbitrary code execution in a browser session.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-81822 |
| CVSS | Not published in the cited sources |
| Vendor / product | AVEVA โ AVEVA Pipeline Integrity Monitor |
| Reported | 2026-09-12 |