Description
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.
Published: 2026-07-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the use of an insufficiently strong encryption algorithm to protect the configuration of user accounts stored in the built‑in user directory of PcVue projects, versions before 17.0.0. A local attacker who can write to the project files can modify the encrypted user configuration, thereby changing account privileges and ultimately obtaining privileged control of the PcVue application. This flaw is classified as CWE-326 and results in privilege escalation.

Affected Systems

Arcinfo PcVue installations that use any version released prior to 17.0.0 are affected. The weak encryption applies to the built‑in user directory of every PcVue project file, regardless of location. No specific sub‑versions are listed beyond the overall threshold of <17.0.0.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability, yet the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of current exploitation. Successful exploitation requires local access to the PcVue file system and the ability to alter the user directory configuration. Attackers who meet these prerequisites could elevate privileges within the PcVue application. No evidence indicates that this flaw can be abused over the network; the description claims only local attack capability. Applying the published patch removes the weak encryption support and eliminates this attack surface.

Generated by OpenCVE AI on July 26, 2026 at 19:28 UTC.

Remediation

Vendor Solution

Harden the configuration Who should apply this recommendation: All users To reduce the risk of exploitation, ARC Informatique strongly recommends implementing the following defensive measures: * Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from insecure networks. * Locate control system networks and remote devices behind firewalls and isolate them from business networks. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices. Additional deployment guidance and recommended practices are available in the product documentation ( Hardening Guide https://www.pcvue.com/ProductHelp/PcVue/en/Content/Deployment/hardening-guide/overview.php ). Update PcVue Who should apply this recommendation: All users using the affected component Apply the corrective update by installing PcVue Initial Release 17.0.0 or later In a patched release, it will no longer be possible to load User directory from earlier versions. Existing projects designed with an earlier version require explicit migration using the ProjectUtility CLI tool. Instructions are provided in the product documentation ( Project Utility CLI reference https://www.pcvue.com/ProductHelp/PcVue/en/Content/Deployment/tools/project-utility-cli.php ). To verify that the patch is applied correctly, you must check that the File version property of the file ./bin/sv32.exe matches release 17.0.0 (17.0.0902.3726) or later, and ensure that any earlier release is no longer used. Available patches: Patch provided in: * PcVue 17.0.0 (17.0.0902.3726)


OpenCVE Recommended Actions

  • Apply the PcVue 17.0.0 or later update, which disables loading of user directories encrypted with weak algorithms.
  • For projects created with earlier releases, run the ProjectUtility CLI tool to migrate user data and prevent legacy directories from loading.
  • Reduce exposure of PcVue devices by isolating control system networks behind firewalls and ensuring remote access is conducted over secure methods such as VPN.

Generated by OpenCVE AI on July 26, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.
Title Weak encryption mechanism for User directory
First Time appeared Arcinfo
Arcinfo pcvue
Weaknesses CWE-326
CPEs cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:*
Vendors & Products Arcinfo
Arcinfo pcvue
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: arcinfo

Published:

Updated: 2026-07-07T12:07:31.124Z

Reserved: 2026-07-06T13:45:32.651Z

Link: CVE-2026-14868

cve-icon Vulnrichment

Updated: 2026-07-07T12:07:17.632Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength