CVE-2026-14868
Analyzed Analyzed - Analysis Complete

Weak Encryption in PcVue User Configuration Allows Privilege Escalation

Vulnerability report for CVE-2026-14868, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-07

Last updated on: 2026-07-09

Assigner: arcinfo

Description

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-07
Last Modified
2026-07-09
Generated
2026-07-15
AI Q&A
2026-07-07
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arcinfo pcvue From 17.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability involves the encryption algorithm used to protect the configuration of user accounts stored in the built-in user directory of PcVue projects in all versions prior to 17.0.0. This encryption is not strong enough to provide the required level of protection.

Because of this weak encryption, a local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application.

Impact Analysis

This vulnerability can allow a local attacker to modify user account configurations and gain privileged access to the PcVue application.

Such unauthorized privileged access could lead to unauthorized control over the application, potentially compromising the security and integrity of the system.

Compliance Impact

The vulnerability involves weak encryption protecting user account configurations, which could allow a local attacker to alter configurations and gain privileged access to the PcVue application.

Such unauthorized access and potential data manipulation could lead to non-compliance with standards and regulations like GDPR and HIPAA, which require strong protection of user data and access controls.

However, specific impacts on compliance are not detailed in the provided information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14868. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart