CVE-2026-82789 Details
Description
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
A vulnerability allowing 'Eval Injection' has been identified in CONPROSYS HMI System (CHS) versions prior to 3.8.0. This vulnerability arises from improper neutralization of directives in dynamically evaluated code, which could enable an attacker to execute arbitrary PHP code. The issue can be exploited by any user who is logged into the application.
Users are advised to update to version 3.8.0 or later. The latest version can be requested through the CONTEC website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU96551518/ | [email protected] | AdvisoryBundleRemedy |
| https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-95 | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Contec CONPROSYS HMI System | < 3.8.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion