---
id: CVE-2020-26867
title: >-
  ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the
  deserialization of untrusted data, which may allow an attacker to remotely
  execute arbitrary code on the web and mobile back-end server.
summary: >-
  ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the
  deserialization of untrusted data, which may allow an attacker to remotely
  execute arbitrary code on the web and mobile back-end server.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
  - CWE-502
vendor: arcinformatique
product: pcvue
affected:
  - 'pcvue >= 8.10, < 12.0.17'
patched:
  - pcvue 12.0.17
published: '2020-10-12'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26867'
references:
  - url: >-
      https://ics-cert.kaspersky.com/advisories/klcert-advisories/2020/10/09/klcert-20-015-remote-code-execution-in-arc-informatique-pcvue/
    label: vulnerability@kaspersky.com
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: vulnerability@kaspersky.com
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: vulnerability@kaspersky.com
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: vulnerability@kaspersky.com
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: vulnerability@kaspersky.com
  - url: 'https://www.pcvuesolutions.com/security'
    label: vulnerability@kaspersky.com
  - url: >-
      https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1076-security-bulletin-2020-1
    label: vulnerability@kaspersky.com
  - url: >-
      https://ics-cert.kaspersky.com/advisories/klcert-advisories/2020/10/09/klcert-20-015-remote-code-execution-in-arc-informatique-pcvue/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.pcvuesolutions.com/security'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1076-security-bulletin-2020-1
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03751
epssPercentile: 0.8947
ingestedAt: '2026-07-09T15:51:17.491Z'
---

## Overview

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

## Affected

- `pcvue >= 8.10, < 12.0.17`

## Remediation

Upgrade past the affected range:

- `pcvue 12.0.17`
