Junglewise Threat Intelligence

CVE-2026-82767: Contec SGA1000 cross-site scripting vulnerability

CVE-2026-82767 · Severity: medium · CVSS 5.2 · Published 2026-09-14

Technologies: Contec SGA1000. Vendors: Contec.

Executive brief

Contec SGA1000 is a network appliance used for industrial automation and data communication. A cross-site scripting vulnerability allows an attacker to inject arbitrary scripts that execute in the web browser of any logged-in user, potentially allowing session hijacking, credential theft, or malicious actions performed on behalf of the victim.

Technical details

CVE-2026-82767 is a cross-site scripting (CWE-79) vulnerability in Contec SGA1000 versions prior to 1.02. The vulnerability requires network access to the product's web interface and an authenticated user to view a malicious page; user interaction (clicking a link) is required. An attacker can craft a malicious webpage containing JavaScript that executes in the context of the victim's browser session, allowing script execution with the privileges of the logged-in user. The vulnerability can be mitigated by updating to version 1.02 or later.

Affected products

  • Contec SGA1000 prior to 1.02

Timeline

  • 2026-09-14: disclosed

References

Related threats