← Vulnerability feed

Vulnerability record · CVE-2026-14868 · published 7 July 2026

CVE-2026-14868: Arcinfo pcvue inadequate encryption strength vulnerability

Arcinfo · Pcvue

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

8.4 CVSS 4.0 High EPSS 0.06% · top 100.0% CWE-326 · Inadequate encryption strength
8.4CVSS 4.0 base score
0.06%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
9 Jul 2026Last modified by NVD

Description

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.pcvue.com/security/#SB2026-5 Vendor Advisory

Track CVE-2026-14868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-26867Arcinfo pcvue deserialization of untrusted data vulnerabilityARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely e…EPSS 3.8%9.3CVE-2011-4042Arcinfo frontvue vulnerabilityAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute a…EPSS 6.4%9.3CVE-2011-4043Arcinfo frontvue vulnerabilityInteger overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote at…EPSS 7.4%7.5CVE-2020-26868Arcinfo pcvue exposure of resource to wrong sphere vulnerabilityARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify info…EPSS 2.2%7.5CVE-2020-26869Arcinfo pcvue information exposure vulnerabilityARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitima…EPSS 1.7%6.8CVE-2026-14867Arcinfo pcvue vulnerabilityCredentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could ret…EPSS 0.13%6.5CVE-2022-4311Arcinfo pcvue sensitive information in log file vulnerabilityAn insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to …EPSS 0.34%5.8CVE-2011-4044Arcinfo frontvue vulnerabilityAn unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify fi…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2026-14868), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.