Home

Description

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.

PUBLISHED Reserved 2026-04-01 | Published 2026-04-15 | Updated 2026-04-15 | Assigner icscert




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-862

Product status

Default status
unaffected

Any version
affected

References

www.aveva.com/...updates/SecurityBulletin_AVEVA-2026-004.pdf

softwaresupportsp.aveva.com/...b-7b5f-4125-8a44-833b6b5c6d6f

www.cisa.gov/news-events/ics-advisories/icsa-26-106-04

github.com/...p/csaf_files/OT/white/2026/icsa-26-106-04.json

cve.org (CVE-2026-5387)

nvd.nist.gov (CVE-2026-5387)

Download JSON