AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-1695

MEDIUM · CVSS 6.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-26 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It may be remotely exploitable.

CVE
CVE-2026-1695
Severity
MEDIUM
CVSS
6.1
EPSS
0.21%

Original NVD Description

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id). This vulnerability only affects the error page of the OAuth server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)