Junglewise Threat Intelligence

CVE-2026-1694: ARC Informatique PcVue Information Exposure via Default HTTP Headers

CVE-2026-1694 · Severity: medium · CVSS 4.3 · Published 2026-02-26

Technologies: ARC Informatique PcVue. Vendors: ARC Informatique.

Executive brief

PcVue, a platform used for monitoring industrial and building automation systems, contains a configuration oversight in its web-based components. The default setup fails to remove certain technical information from the server's responses, which can reveal details about the underlying software environment to unauthorized users. While this does not directly allow for a system takeover, it provides attackers with reconnaissance data that could be used to plan more sophisticated targeted attacks.

Technical details

PcVue (versions 12.0.0 to 16.3.3) suffers from an information exposure vulnerability (CWE-201) due to insecure default configurations in its web services components, including WebVue, WebScheduler, TouchVue, and SnapVue. The application fails to strip default IIS and ASP.NET HTTP headers (such as 'X-Powered-By' or 'Server') during the deployment phase. A remote, unauthenticated attacker can observe these headers in HTTP responses to gain technical intelligence about the server's environment and versioning. This reconnaissance data can facilitate the identification of further vulnerabilities specific to the underlying stack. The issue is addressed in version 16.3.4 and later.

Affected products

  • ARC Informatique (arcinfo) PcVue 12.0.0 through 16.3.3

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: advisory

References

Related threats