PT-2026-22124 · Pcvue+4 · Pcvue+4

CVE-2026-1692

·

Published

2026-02-26

·

Updated

2026-07-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PcVue versions 12.0.0 through 16.3.3
Description A missing origin validation in WebSockets can affect the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features. This could allow a remote attacker to redirect a successfully authenticated user to a malicious website. The issue is present in the following API endpoints: /GraphicalData/js/signalR/connect and /GraphicalData/js/signalR/reconnect.
Recommendations Versions 12.0.0 through 16.3.3 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1692

Affected Products

Pcvue
Snapvue
Touchvue
Web Schedule
Webvue