Junglewise Threat Intelligence

CVE-2026-14867: ARC Informatique PcVue plaintext storage of credentials in User directory

CVE-2026-14867 · Severity: info · CVSS 6.8 · Published 2026-07-07

Technologies: ARC Informatique PcVue. Vendors: ARC Informatique.

Executive brief

PcVue is a software platform used for monitoring and controlling industrial systems like power grids, water treatment, and building automation. A security flaw in older versions allows a person with local access to the computer to retrieve the login credentials of built-in users. This could allow an unauthorized individual to gain higher-level access to the control system, potentially disrupting operations or viewing sensitive industrial data.

Technical details

A plaintext storage of passwords vulnerability (CWE-256) exists in ARC Informatique PcVue. The credentials for built-in user accounts are stored insecurely within the 'User' directory of PcVue projects. A local attacker with low privileges can access these files to retrieve credentials, potentially leading to unauthorized administrative access to the SCADA/HMI platform. This vulnerability does not affect Active Directory-integrated accounts. The issue is resolved in version 17.0.0.

Affected products

  • ARC Informatique PcVue All versions prior to 17.0.0

Timeline

  • 2026-07-07: advisory
  • 2026-07-07: disclosed

References

Related threats