AVEVA Process Optimization Privilege Escalation Vulnerability

Vulnerability

A vulnerability in AVEVA Process Optimization (formerly ROMeo) versions through 2024.1 has been identified, allowing an authenticated user to manipulate the Process Optimization services into executing arbitrary code. This exploitation could escalate privileges to the operating system level, potentially leading to a complete compromise of the Model Application Server.

Impact

Exploitation of this vulnerability could allow an authenticated user to execute arbitrary code with elevated privileges, potentially compromising the entire Model Application Server.

Remediation

Users can refer to the AVEVA Security Bulletin AVEVA-2026-001 for guidance on applying the security update. This bulletin is available on the AVEVA website.

Added: Jan 16, 2026, 2:19 AM
Updated: Jan 16, 2026, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.