Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-14868 +1 in the same advisory: …14867 | The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0 The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application. NVD description · AI analysis pending | 8.4 group max | <1% |
| — | ||
| CVE-2026-1693 | The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue fe The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2022-4311 +1 in the same advisory: …4312 | An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2022-2569 | The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belongi The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2020-26867 | ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbi ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server. NVD description · AI analysis pending | 9.8 group max | 4% |
| — |