Junglewise Threat Intelligence

CVE-2026-1693: ARC Informatique PcVue use of deprecated OAuth ROPC flow

CVE-2026-1693 · Severity: high · CVSS 7.5 · Published 2026-02-26

Technologies: ARC Informatique PcVue. Vendors: ARC Informatique.

Executive brief

PcVue is a monitoring and control platform used in industrial environments like power plants and smart buildings. A security issue exists where several of its web-based components use an outdated and insecure method for handling user logins. This could allow a remote attacker to intercept or steal user credentials, potentially leading to unauthorized access to industrial control systems.

Technical details

PcVue versions 12.0.0 through 16.3.3 utilize the deprecated OAuth 2.0 Resource Owner Password Credentials (ROPC) grant type within the web services supporting WebVue, WebScheduler, TouchVue, and SnapVue. ROPC is considered insecure because it requires the client application to handle and transmit the user's cleartext credentials directly, increasing the risk of credential exposure and making it difficult to implement multi-factor authentication. A remote attacker could exploit this weak authentication architecture to intercept or steal user credentials. The vulnerability is categorized under CWE-477 (Use of Obsolete Function) and CWE-1390 (Weak Authentication). Users should upgrade to version 16.3.4 or later to mitigate this risk.

Affected products

  • ARC Informatique PcVue 12.0.0 through 16.3.3

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: advisory

References

Related threats