CVE-2026-1694

MEDIUM

PcVue 12.0.0-16.3.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (4)
arcinfo/PcVue 12.0.0
arcinfo/PcVue 15.0.0 - 15.2.13
arcinfo/PcVue 16.0.0 - 16.3.3
arcinformatique/pcvue 12.0.0 - 15.2.13
Published Feb 26, 2026
Tracked Since Feb 26, 2026