---
id: CVE-2026-1693
title: >-
  The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still
  used by the werbservices used by the WebVue, WebScheduler, TouchVue and
  Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite
  being depre…
summary: >-
  The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still
  used by the werbservices used by the WebVue, WebScheduler, TouchVue and
  Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite
  being depre…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-477
  - CWE-1390
vendor: arcinfo
product: pcvue
affected:
  - 'pcvue >= 12.0.0, <= 15.2.13'
  - 'pcvue >= 16.0.0, < 16.3.4'
patched:
  - pcvue 16.3.4
published: '2026-02-26'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1693'
references:
  - url: 'https://www.pcvue.com/security/#SB2026-2'
    label: 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932
tags:
  - nvd
epss: 0.00314
epssPercentile: 0.24537
ingestedAt: '2026-07-10T01:55:22.927Z'
---

## Overview

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.

## Affected

- `pcvue >= 12.0.0, <= 15.2.13`
- `pcvue >= 16.0.0, < 16.3.4`

## Remediation

Upgrade past the affected range:

- `pcvue 16.3.4`
