Junglewise Threat Intelligence

CVE-2026-1692: ARC Informatique PcVue Missing Origin Validation in WebSockets

CVE-2026-1692 · Severity: medium · CVSS 6.1 · Published 2026-02-26

Technologies: ARC Informatique PcVue. Vendors: ARC Informatique.

Executive brief

A security vulnerability exists in PcVue, a software platform used for monitoring industrial and building automation systems. The flaw affects web-based features like WebVue and TouchVue, potentially allowing a remote attacker to trick an authenticated user into visiting a malicious website. This could lead to unauthorized actions being performed on the user's behalf within the monitoring system.

Technical details

A missing origin validation vulnerability (CWE-1385) exists in the GraphicalData web services of PcVue. The flaw specifically affects the SignalR WebSocket endpoints 'GraphicalData/js/signalR/connect' and 'GraphicalData/js/signalR/reconnect'. Because the application fails to properly validate the 'Origin' header during the WebSocket handshake, a remote attacker can lure an authenticated user to a malicious site that initiates a WebSocket connection to the vulnerable server. This allows the attacker to interact with the web service using the victim's session context. The vulnerability impacts versions 12.0.0 through 16.3.3 and is addressed in version 16.3.4 and other recent patches.

Affected products

  • ARC Informatique PcVue 12.0.0 through 16.3.3

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: advisory

References

Related threats