CVE-2026-5387
Received
Received - Intake
Privilege Escalation in Simulator Software via Unauthorized Role Access
Publication date: 2026-04-15
Last updated on: 2026-04-15
Assigner: ICS-CERT
Description
Description
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aveva | pipeline_simulation | to 2025_sp1_p01 (exc) |
| aveva | pipeline_simulation | to 2025_sp1 (exc) |
| aveva | pipeline_simulation | From 2025_sp1_p01 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |