CVE-2026-1698
CVE-2026-1698 is a medium-severity vulnerability in Arcinfo Pcvue with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-644.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (10th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-8842
- Weakness: CWE-644
- Affected product: Arcinfo Pcvue
- Published:
- Last modified:
Description
A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps.
Frequently asked questions
- What is CVE-2026-1698?
- A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps.
- How severe is CVE-2026-1698?
- CVE-2026-1698 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-1698 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (10th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-1698?
- CVE-2026-1698 affects Arcinfo Pcvue. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-1698?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-1698 have an EU (EUVD) identifier?
- Yes. CVE-2026-1698 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-8842.
- When was CVE-2026-1698 published?
- CVE-2026-1698 was published on 2026-02-26 and last updated on 2026-07-09.
References
Affected products (1)
- cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*
More vulnerabilities in Arcinfo Pcvue
- CVE-2020-26867 — Critical (CVSS 9.8): ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may…
- CVE-2011-4043 — Critical (CVSS 9.3): Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue,…
- CVE-2011-4042 — Critical (CVSS 9.3): An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows…
- CVE-2026-1693 — High (CVSS 7.5): The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the…
- CVE-2020-26869 — High (CVSS 7.5): ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to…
- CVE-2020-26868 — High (CVSS 7.5): ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an…
All CVEs affecting Arcinfo Pcvue →
Other CWE-644 vulnerabilities
- CVE-2025-70948 — Critical (CVSS 9.3): A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain…
- CVE-2026-26747 — Critical (CVSS 9.1): A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in…
- CVE-2026-26234 — High (CVSS 8.8): JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated…
- CVE-2023-32465 — High (CVSS 8.8): Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially…
- CVE-2026-33805 — High (CVSS 8.6): @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection…
- CVE-2025-64484 — High (CVSS 8.5): OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component…