Junglewise Threat Intelligence

CVE-2026-1698: ARC Informatique PcVue HTTP Host header attack in WebClient and WebScheduler

CVE-2026-1698 · Severity: medium · CVSS 6.1 · Published 2026-02-26

Technologies: ARC Informatique PcVue. Vendors: ARC Informatique.

Executive brief

A security vulnerability exists in the WebClient and WebScheduler components of PcVue, a platform used for monitoring industrial and building automation systems. An attacker can send specially crafted web requests to manipulate how the server handles authentication and logout processes. This could lead to unauthorized redirection or the injection of malicious content, potentially compromising user sessions or misleading operators.

Technical details

A HTTP Host header attack vulnerability (CWE-644) exists in the WebClient and WebScheduler web applications of PcVue. The issue stems from improper neutralization of the Host header in the /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback, and /Authentication/Logout endpoints. A remote, unauthenticated attacker can exploit this by submitting a malicious Host header, allowing for the injection of harmful payloads that manipulate server-side behavior, such as password reset poisoning or web cache poisoning. The vulnerability is addressed in versions 15.2.14 and 16.3.4.

Affected products

  • ARC Informatique PcVue 15.0.0 through 15.2.13, 16.0.0 through 16.3.3

Timeline

  • 2026-02-26: advisory: Initial publication of CVE-2026-1698
  • 2026-02-26: disclosed: Vendor advisory SB2026-2 released

References

Related threats