Executive brief
Contec SGA1000 is a network appliance used for industrial automation and data communication. A cross-site scripting vulnerability allows an attacker to inject arbitrary scripts that execute in the web browser of any logged-in user, potentially allowing session hijacking, credential theft, or malicious actions performed on behalf of the victim.
Technical details
CVE-2026-82767 is a cross-site scripting (CWE-79) vulnerability in Contec SGA1000 versions prior to 1.02. The vulnerability requires network access to the product's web interface and an authenticated user to view a malicious page; user interaction (clicking a link) is required. An attacker can craft a malicious webpage containing JavaScript that executes in the context of the victim's browser session, allowing script execution with the privileges of the logged-in user. The vulnerability can be mitigated by updating to version 1.02 or later.
Affected products
- Contec SGA1000 prior to 1.02
Timeline
- 2026-09-14: disclosed