PT-2026-22125 · Pcvue+4 · Pcvue+4

Published

2026-02-26

·

Updated

2026-03-12

·

CVE-2026-1693

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PcVue versions 12.0.0 through 16.3.3
Description The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still utilized by the web services supporting the WebVue, WebScheduler, TouchVue, and Snapvue features. This practice, despite the flow being deprecated, could enable a remote attacker to obtain user credentials.
Recommendations Versions 12.0.0 through 16.3.3 should discontinue the use of the Resource Owner Password Credentials (ROPC) OAuth grant type flow for the WebVue, WebScheduler, TouchVue, and Snapvue features.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-1693

Affected Products

Pcvue
Snapvue
Touchvue
Web Schedule
Webvue