Executive Summary

Industrial software vendor AVEVA, in coordination with CISA, has published a critical security advisory addressing a local privilege escalation flaw in AVEVA System Platform (incorporating InTouch HMI and the underlying Operations Integration Server suite). The vulnerability, tracked as CVE-2026-54890, carries a CVSS v3.1 base score of 7.8 (High) and impacts installations across oil and gas refineries, food and beverage packaging plants, and pharmaceuticals manufacturing sites.

The flaw enables an unprivileged user—such as a plant floor operator or contract maintenance technician logged into an HMI terminal with restricted rights—to elevate privileges to NT AUTHORITY\SYSTEM, gaining complete control over the engineering workstation.

Root Cause Analysis: Weak ACLs on OPC DA/UA Helper Binaries

During installation, the AVEVA System Platform creates dedicated directories under C:\ProgramData\Wonderware\OI-Server\ and C:\Program Files (x86)\Common Files\ArchestrA\ to host OPC driver configuration databases and background synchronization binaries. Due to an oversight in the Windows installer script, these directories inherited permissive access control lists (ACLs) granting write access to the Authenticated Users group.

Because the main supervisory service (ArchestrA.Watchdog.exe) runs permanently under the high-privilege SYSTEM account and periodically spawns auxiliary diagnostics binaries from these shared directories without verifying binary digital signatures, a local attacker can replace a legitimate helper DLL or executable with a malicious payload, triggering automatic execution during routine HMI polling cycles.

# Auditing directory permissions on affected InTouch workstation
Get-Acl "C:\ProgramData\Wonderware\OI-Server\" | Format-List
# Vulnerable ACL output showed:
# IdentityReference: NT AUTHORITY\Authenticated Users
# FileSystemRights : Modify, Synchronize
# AccessControlType: Allow

Operational Impact on Industrial Operations

In industrial control architectures conforming to IEC 62443, HMI operator consoles are often shared among multiple shifts and protected by kiosk software designed to prevent operators from launching unauthorized desktop tools. Bypassing these restrictions to obtain full SYSTEM access allows an adversary to:

  • Disable endpoint detection and response (EDR) software protecting the supervisory tier.
  • Tamper with InTouch historical alarm databases and production batch records.
  • Deploy ransomware across the operational network, halting manufacturing output.

Remediation Playbook

AVEVA has published official cumulative service packs and guidance for affected installations:

  1. Apply Service Pack: Install AVEVA System Platform 2023 R2 SP1 or apply Hotfix HF-54890 to versions 2020 and 2023.
  2. Remediate Folder ACLs: Run the official AVEVA PowerShell hardening script to remove write permissions from Authenticated Users across all ArchestrA and Wonderware installation directories:
    icacls "C:\ProgramData\Wonderware" /inheritance:r /grant:r "Administrators:(OI)(CI)F" "SYSTEM:(OI)(CI)F"
  3. Enforce Principle of Least Privilege: Implement strict group policy objects (GPOs) preventing operator accounts from accessing local administrative tools or external removable media.