A local attacker could alter existing configurations and gain privileged access to the PcVue application due to a weak encryption algorithm used for user account configurations in PcVue projects prior to version 17.0.0. This issue arises from the insufficient strength of the encryption algorithm protecting user account configurations stored in the built-in user directory of PcVue projects. The vulnerabili [truncated]
CVE-2026-14867 is a vulnerability in PcVue projects where credentials of built-in users are stored insecurely in the User directory. This issue affects all versions prior to 17.0.0 and allows a local attacker to retrieve users' credentials. Active Directory accounts are not affected. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 2026-07-07T10:16:40.120 [truncated]
A vulnerability was found in PcVue versions 12.0.0 through 16.3.3, where the GraphicalData web services and WebClient web app are missing Secure and SameSite attributes. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability could potentially allow attackers to exploit the system. Administrators and users of affected versions should be aware of this vulnerability and ta [truncated]
CVE-2026-1696 is a low-severity vulnerability affecting Arcinfo Pcvue, a product used for monitoring and control. The web server does not properly set some HTTP security headers in responses to client applications, potentially allowing attackers to exploit the vulnerability. Although the CVSS score is low at 2.3, users of affected versions should apply vendor patches to address this issue. The vulnerabili [truncated]
CVE-2026-1695 is a MEDIUM severity XSS vulnerability affecting PcVue's OAuth web services. The vulnerability exists in versions 12.0.0 through 16.3.3 and could allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication. This type of vulnerability typically requires user interaction to exploit and can have significant impacts if not prope [truncated]
CVE-2026-1694 is a low-severity vulnerability affecting PcVue versions 12.0.0 through 16.3.3. The default configuration of IIS and ASP.net adds HTTP headers that are not removed during the deployment phase of certain features, unnecessarily exposing sensitive server configuration information. This vulnerability has a CVSS score of 2.3 and is considered low severity. Organizations should review their deplo [truncated]
CVE-2026-1693 is a vulnerability in PcVue, a product by Arcinfo, that uses the deprecated OAuth grant type Resource Owner Password Credentials (ROPC) flow. This might allow a remote attacker to steal user credentials. The affected versions are 12.0.0 through 16.3.3. The CVSS score for this vulnerability is 5.3, and the severity is MEDIUM. Organizations should review their PcVue deployments for exposure.