Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5387

30
FAUCET Score

CVE-2026-5387 is an authentication bypass vulnerability affecting simulator training systems that allows unauthenticated attackers to assume Simulator Instructor or Administrator privileges. The flaw enables unauthorized users to modify critical simulation parameters, training configurations, and training records without proper access controls. This represents a significant integrity and confidentiality risk for organizations relying on these systems for training purposes. The vulnerability has a FAUCET Risk Score of 53.0/100, indicating moderate concern, though no CVSS vector data is currently available. The attack requires no authentication and likely has low complexity, making it relatively accessible to potential threat actors. Successful exploitation could result in privilege escalation with broad impacts across simulation environment management and training data integrity. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is listed as inactive on threat intelligence platforms. The EPSS score of 0.00054 suggests very low probability of exploitation in the next 30 days. However, organizations should still prioritize patching given the severity of potential impacts and the ease of exploitation once the vulnerability becomes public knowledge.

Impacted Technologies

VendorProductVersion(s)CPE
AVEVAPipeline Simulation 2025
>= 0, <= 2025 SP1 (build 7.1.9497.6351)CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 8th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-04.json
softwaresupportsp.aveva.com / en-US/downloads/products/details/57b79fdb-7b5f-4125-8a44-833b6b5c6d6f
aveva.com / content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-004.pdf
cisa.gov / news-events/ics-advisories/icsa-26-106-04