CVE Vulnerabilities

CVE-2026-1697

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Published: Feb 26, 2026 | Modified: Mar 12, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

Weakness

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Affected Software

NameVendorStart VersionEnd Version
PcvueArcinformatique12.0.0 (including)15.2.13 (including)
PcvueArcinformatique16.0.0 (including)16.3.4 (excluding)

Potential Mitigations

References