PatchSiren

arcinfo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH arcinfo CVE published 2026-07-07

CVE-2026-14868

A local attacker could alter existing configurations and gain privileged access to the PcVue application due to a weak encryption algorithm used for user account configurations in PcVue projects prior to version 17.0.0. This issue arises from the insufficient strength of the encryption algorithm protecting user account configurations stored in the built-in user directory of PcVue projects. The vulnerabili [truncated]

MEDIUM arcinfo CVE published 2026-07-07

CVE-2026-14867

CVE-2026-14867 is a vulnerability in PcVue projects where credentials of built-in users are stored insecurely in the User directory. This issue affects all versions prior to 17.0.0 and allows a local attacker to retrieve users' credentials. Active Directory accounts are not affected. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 2026-07-07T10:16:40.120 [truncated]

MEDIUM arcinfo CVE published 2026-02-26

CVE-2026-1697

A vulnerability was found in PcVue versions 12.0.0 through 16.3.3, where the GraphicalData web services and WebClient web app are missing Secure and SameSite attributes. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability could potentially allow attackers to exploit the system. Administrators and users of affected versions should be aware of this vulnerability and ta [truncated]

LOW Arcinfo CVE published 2026-02-26

CVE-2026-1696

CVE-2026-1696 is a low-severity vulnerability affecting Arcinfo Pcvue, a product used for monitoring and control. The web server does not properly set some HTTP security headers in responses to client applications, potentially allowing attackers to exploit the vulnerability. Although the CVSS score is low at 2.3, users of affected versions should apply vendor patches to address this issue. The vulnerabili [truncated]

MEDIUM arcinfo CVE published 2026-02-26

CVE-2026-1695

CVE-2026-1695 is a MEDIUM severity XSS vulnerability affecting PcVue's OAuth web services. The vulnerability exists in versions 12.0.0 through 16.3.3 and could allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication. This type of vulnerability typically requires user interaction to exploit and can have significant impacts if not prope [truncated]

LOW arcinfo CVE published 2026-02-26

CVE-2026-1694

CVE-2026-1694 is a low-severity vulnerability affecting PcVue versions 12.0.0 through 16.3.3. The default configuration of IIS and ASP.net adds HTTP headers that are not removed during the deployment phase of certain features, unnecessarily exposing sensitive server configuration information. This vulnerability has a CVSS score of 2.3 and is considered low severity. Organizations should review their deplo [truncated]

MEDIUM arcinfo CVE published 2026-02-26

CVE-2026-1693

CVE-2026-1693 is a vulnerability in PcVue, a product by Arcinfo, that uses the deprecated OAuth grant type Resource Owner Password Credentials (ROPC) flow. This might allow a remote attacker to steal user credentials. The affected versions are 12.0.0 through 16.3.3. The CVSS score for this vulnerability is 5.3, and the severity is MEDIUM. Organizations should review their PcVue deployments for exposure.