Executive brief
A security vulnerability exists in the PcVue industrial monitoring platform, specifically affecting its web-based interfaces and mobile applications. An attacker could trick a legitimate user into interacting with a malicious link that loads unauthorized content through the platform's login error pages. This could lead to unauthorized actions being performed in the user's session or the theft of sensitive information, potentially compromising the monitoring and control of industrial systems.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the OAuth server component of PcVue. The flaw is located within the error page generation logic of the OAuth web services. An unauthenticated remote attacker can exploit this by crafting a malicious URL (e.g., using an unknown client_id) that, when visited by a legitimate user, executes arbitrary script in the context of the user's browser session. This affects several features including WebVue, WebScheduler, TouchVue, and SnapVue. The vulnerability is addressed in version 16.3.4 and other subsequent maintenance releases.
Affected products
- ARC Informatique PcVue 12.0.0 through 16.3.3
Timeline
- 2026-02-26: disclosed
- 2026-02-26: advisory