← Vulnerability feed

Vulnerability record · CVE-2020-26868 · published 12 October 2020

CVE-2020-26868: Arcinfo pcvue exposure of resource to wrong sphere vulnerability

Arcinfo · Pcvue

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.

7.5 CVSS 3.1 High EPSS 2.2% · top 18.6% CWE-767 · CWE-767CWE-668 · Exposure of resource to wrong sphere
7.5CVSS 3.1 base score, v2 5.0
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
9 Jul 2026Last modified by NVD

Description

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-26867Arcinfo pcvue deserialization of untrusted data vulnerabilityARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely e…EPSS 3.8%9.3CVE-2011-4042Arcinfo frontvue vulnerabilityAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute a…EPSS 6.4%9.3CVE-2011-4043Arcinfo frontvue vulnerabilityInteger overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote at…EPSS 7.4%8.4CVE-2026-14868Arcinfo pcvue inadequate encryption strength vulnerabilityThe encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions pr…EPSS 0.06%7.5CVE-2020-26869Arcinfo pcvue information exposure vulnerabilityARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitima…EPSS 1.7%6.8CVE-2026-14867Arcinfo pcvue vulnerabilityCredentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could ret…EPSS 0.13%6.5CVE-2022-4311Arcinfo pcvue sensitive information in log file vulnerabilityAn insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to …EPSS 0.34%5.8CVE-2011-4044Arcinfo frontvue vulnerabilityAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify fi…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2020-26868), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.