CVE-2026-5387 is an authentication bypass vulnerability affecting simulator training systems that allows unauthenticated attackers to assume Simulator Instructor or Administrator privileges. The flaw enables unauthorized users to modify critical simulation parameters, training configurations, and training records without proper access controls. This represents a significant integrity and confidentiality risk for organizations relying on these systems for training purposes. The vulnerability has a FAUCET Risk Score of 53.0/100, indicating moderate concern, though no CVSS vector data is currently available. The attack requires no authentication and likely has low complexity, making it relatively accessible to potential threat actors. Successful exploitation could result in privilege escalation with broad impacts across simulation environment management and training data integrity. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is listed as inactive on threat intelligence platforms. The EPSS score of 0.00054 suggests very low probability of exploitation in the next 30 days. However, organizations should still prioritize patching given the severity of potential impacts and the ease of exploitation once the vulnerability becomes public knowledge.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AVEVA | Pipeline Simulation 2025 | >= 0, <= 2025 SP1 (build 7.1.9497.6351)CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.