# CVE-2026-1697

## Summary

- **CVE ID:** CVE-2026-1697
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/AU:Y/R:U/RE:M/U:Clear)
- **CWE:** CWE-614, CWE-1275
- **Published:** Feb 26, 2026
- **Last Modified:** Mar 26, 2026

## Description

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

## Affected Products

- arcinfo — PcVue (16.0.0)
- arcinfo — PcVue (15.0.0)
- arcinfo — PcVue (12.0.0)

## References

- [CNA](https://www.pcvue.com/security/#SB2026-2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 1.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._