CVE-2026-1495: Aveva Pi To Connect Agent

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.

Affected products

  • Aveva Pi To Connect Agent: up to and including v2.4.2520

Published 2026-02-10. Last modified 2026-06-17.