---
id: CVE-2026-1692
title: >-
  A missing origin validation in WebSockets vulnerability affects the
  GraphicalData web services used by the WebVue, WebScheduler, TouchVue and
  SnapVue features of PcVue in version 12.0.0 through 16.3.3 included
summary: >-
  A missing origin validation in WebSockets vulnerability affects the
  GraphicalData web services used by the WebVue, WebScheduler, TouchVue and
  SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might
  allow a remote at…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-1385
vendor: arcinfo
product: pcvue
affected:
  - 'pcvue >= 12.0.0, <= 15.2.13'
  - 'pcvue >= 16.0.0, < 16.3.4'
patched:
  - pcvue 16.3.4
published: '2026-02-26'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1692'
references:
  - url: 'https://www.pcvue.com/security/#SB2026-2'
    label: 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932
tags:
  - nvd
epss: 0.00111
epssPercentile: 0.01518
ingestedAt: '2026-07-10T01:55:22.924Z'
---

## Overview

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website.

This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect.

## Affected

- `pcvue >= 12.0.0, <= 15.2.13`
- `pcvue >= 16.0.0, < 16.3.4`

## Remediation

Upgrade past the affected range:

- `pcvue 16.3.4`
