---
id: CVE-2026-1694
title: >-
  HTTP headers are added by the default configuration of IIS and ASP.net, and
  are not removed at the deployment phase of the webservices used by the WebVue,
  WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through
  16.…
summary: >-
  HTTP headers are added by the default configuration of IIS and ASP.net, and
  are not removed at the deployment phase of the webservices used by the WebVue,
  WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through
  16.…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-201
vendor: arcinfo
product: pcvue
affected:
  - 'pcvue >= 12.0.0, <= 15.2.13'
  - 'pcvue >= 16.0.0, < 16.3.4'
patched:
  - pcvue 16.3.4
published: '2026-02-26'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1694'
references:
  - url: 'https://www.pcvue.com/security/#SB2026-2'
    label: 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932
tags:
  - nvd
epss: 0.00168
epssPercentile: 0.05364
ingestedAt: '2026-07-10T01:55:22.930Z'
---

## Overview

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration.

## Affected

- `pcvue >= 12.0.0, <= 15.2.13`
- `pcvue >= 16.0.0, < 16.3.4`

## Remediation

Upgrade past the affected range:

- `pcvue 16.3.4`
