VYPR
Medium severity6.1NVD Advisory· Published Feb 26, 2026· Updated Jul 9, 2026

CVE-2026-1695

CVE-2026-1695

Description

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id).

This vulnerability only affects the error page of the OAuth server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Arcinfo/Pcvue2 versions
    cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*range: >=12.0.0,<=15.2.13
    • (no CPE)range: 16.0.0
  • PcVue/PcVuellm-fuzzy
    Range: 12.0.0 - 16.3.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.