CVE-2026-5387Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-15: 1Active Exploitation · 2026-04-17: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 104-1504-1604-17
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-161
Disclosure1
2026-04-171
Active Exploitation1
Full discourse3 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-5387 to gain unauthorized access to AVEVA Pipeline Simulation systems, then escalating privileges to modify critical simulation parameters. The attack demonstrates how missing authorization controls enable lateral movement across industrial networks. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/aveva-pipeline-simulation-2026-missing-authorization

    Post summary

    Attackers exploited CVE-2026-5387 to access AVEVA Pipeline Simulation systems, elevate privileges, and modify critical parameters, demonstrating how missing authorization controls allow lateral movement across industrial networks.

    0000048
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5387 The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administr… https://www.cve.org/CVERecord?id=CVE-2026-5387

    Post summary

    A simple reference to CVE-2026-5387’s existence as a privilege escalation vulnerability for unauthenticated users is presented, without additional technical, exploit, or mitigation details.

    00000103
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5387: AVEVA Pipeline Simulation Missing... Unauthenticated network access to AVEVA's critical infrastructure simulator with full admin privs - attackers can poison... https://zerodaysignal.com/vulnerability/CVE-2026-5387 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post reports the disclosure of CVE‑2026‑5387, noting that unauthenticated network access to AVEVA Pipeline Simulation can grant full admin rights and enable system poisoning. No active exploitation, patches, or PoC code are detailed in the excerpt.

    0000066
    218 followersView on X

Explore more