# CVE-2026-1698

## Summary

- **CVE ID:** CVE-2026-1698
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/AU:Y/R:U/RE:M/U:Clear)
- **CWE:** CWE-644
- **Published:** Feb 26, 2026
- **Last Modified:** Mar 26, 2026

## Description

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior.

This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout
of the WebClient and WebScheduler web apps.

## Affected Products

- arcinfo — PcVue (16.0.0)
- arcinfo — PcVue (15.0.0)

## References

- [CNA](https://www.pcvue.com/security/#SB2026-2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._