SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-1696

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

LOW 2.3EPSS 0.14%

Does this matter?

Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.

Description

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

CVSS 4.0
2.3 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.14% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
arcinfo/pcvue
Source
87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.