Home

Description

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect.

PUBLISHED Reserved 2026-01-30 | Published 2026-02-26 | Updated 2026-02-26 | Assigner arcinfo




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:Y/R:U/RE:M/U:Clear

Problem types

CWE-1385 Missing Origin Validation in WebSockets

Product status

Default status
unaffected

16.0.0 (cpe)
affected

15.0.0 (cpe)
affected

12.0.0 (cpe)
affected

References

www.pcvue.com/security/ vendor-advisory

cve.org (CVE-2026-1692)

nvd.nist.gov (CVE-2026-1692)

Download JSON