ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HArcinfo Pcvue
APPArcinfo8.10 – 12.0.17 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
References
Related vulnerabilities
CVE-2026-14868HIGH8.4PL ✓same product
Słaby algorytm szyfrowania konfiguracji kont w PcVue
CVE-2020-26868HIGH7.5same product
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability...
CVE-2020-26869HIGH7.5same product
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized u...
CVE-2011-4042HIGH9.3same product
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantV...
CVE-2011-4043HIGH9.3same product
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, ...