CVE-2026-14867
Severity CVSS v4.0:
MEDIUM
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
07/07/2026
Last modified:
09/07/2026
Description
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. <br />
<br />
Active Directory accounts are not affected by this vulnerability.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:arcinfo:pcvue:*:*:*:*:*:*:*:* | 17.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



