CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2020-26867

Critical · CVSS 9.8

ARC Informatique PcVue — Deserialization of untrusted data RCE (CWE-502)

CVSS
9.8
nvd
EPSS
3.72%
88th pct
KEV
No
Class
other
CWE-502, CWE-502

Description

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

Search profile — drives PoC discovery

Symbols deserializationuntrusted dataweb back-end servermobile back-end serverPcVueremote code execution
Keywords CVE-2020-26867PcVue deserialization RCEARC Informatique PcVue exploitPcVue 12.0.17 vulnerabilityKLCERT-20-015ICSA-20-308-03PcVue proof of conceptPcVue PoCARC Informatique RCE
Versions: prior to 12.0.17

References

Status: enriched · ingested 2026-07-09T18:00:39.000Z · profiled 2026-07-09T18:30:39.000Z