peter bassill · operator
$ cve CVE-2020-26867 JSON

CVE-2020-26867

9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.75% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-10-12
Last modified2026-07-09

Affected (1)

VendorProduct
arcinfopcvue

References

→ the Explorer  ·  watch your stack  ·  NVD