CVE-2026-1693
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, Tou
CVSS
7.5
Alto
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 26 feb 2026 · Última mod.: 9 jul 2026 · CWE-477 · CWE-1390
0.3%EPSS · 30 días0.3%
2026-08-142026-09-11
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-774838.8 ALT43.6%
——13Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.3dCVE-2026-730259.8 CRÍ58.3%
——17Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.3dCVE-2026-628958.8 ALT51.8%
——16Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.2dCVE-2026-802198.7 ALT13.8%
——4A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.1dCVE-2026-738199.8 CRÍ43.1%
——13The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenticated attacker on the adjacent
network could modify critical settings or change access credentials,
potentially preventing legitimate administrators from managing the
device.11dCVE-2026-650988.1 ALT49.9%
——15NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.11d