MEDIUM🇵🇱 Wersja polska

CVE-2026-1693

CVSS 5.3v4.0pub. 2026-02-26upd. 2026-07-09

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Clear
  • Arcinfo Pcvue

    APP
    Arcinfo
    12.0.0 – 15.2.1316.0.0 – 16.3.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-26867CRITICAL9.8PL ✓same product

RCE poprzez deserializację niezaufanych danych w ARC Informatique PcVue

CVE-2026-14868HIGH8.4PL ✓same product

Słaby algorytm szyfrowania konfiguracji kont w PcVue

CVE-2020-26868HIGH7.5same product

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability...

CVE-2020-26869HIGH7.5same product

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized u...

CVE-2011-4042HIGH9.3same product

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantV...