CVE-2026-14868 Details
Description
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.
A vulnerability exists in all PcVue versions prior to 17.0.0, where the encryption algorithm protecting user account configurations in the built-in user directory is insufficient. This weakness allows a local attacker to modify the configuration and potentially gain privileged access to the PcVue application.
Users can upgrade to PcVue version 17.0.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2026CNA
Assessed Jan 1, 1References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.pcvue.com/security/#SB2026-5 | arcinfo | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | arcinfo |
Affected Products
| Product | Versions |
|---|---|
| arcinfo pcvue | < 17.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CPE Deprecation Remap | [email protected] |
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | arcinfo |