PT-2026-22124 · Pcvue+4 · Pcvue+4
Published
2026-02-26
·
Updated
2026-03-12
·
CVE-2026-1692
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PcVue versions 12.0.0 through 16.3.3
Description
A missing origin validation in WebSockets can affect the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features. This could allow a remote attacker to redirect a successfully authenticated user to a malicious website. The issue is present in the following API endpoints:
/GraphicalData/js/signalR/connect and /GraphicalData/js/signalR/reconnect.Recommendations
Versions 12.0.0 through 16.3.3 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pcvue
Snapvue
Touchvue
Web Schedule
Webvue