Junglewise Threat Intelligence

CVE-2026-82776: Contec CONPROSYS PAC Series cross-site scripting

CVE-2026-82776 · Severity: medium · CVSS 6.1 · Published 2026-09-14

Vendors: Contec.

Executive brief

CONPROSYS PAC Series is an industrial automation controller used in factory and manufacturing environments to manage machine operations and data collection. A cross-site scripting vulnerability allows attackers to execute arbitrary JavaScript code in the browsers of logged-in operators or administrators, potentially enabling them to steal credentials, manipulate system settings, or access sensitive operational data displayed in the web interface.

Technical details

This is a CWE-79 (Cross-site Scripting / XSS) vulnerability in the CONPROSYS PAC Series web interface. The vulnerability occurs because user-supplied input is not properly sanitized before being rendered in the victim's browser. An attacker can craft a malicious link or inject payload via a vulnerable parameter; when a logged-in user visits or interacts with the malicious content, the arbitrary script executes in their session context. No authentication is required to craft the attack, but the victim must be logged in for the script to have access to sensitive operations. The vulnerability affects CONPROSYS PAC integrated models (CPS-PC341*) and configurable models (CPS-PCS341*) prior to version 3.0.0. Patches are available in version 3.0.0 and later.

Affected products

  • Contec CONPROSYS PAC Series Integrated Type CPS-PC341*-*-9201 and Configurable Type CPS-PCS341*-DS1-1201 versions prior to 3.0.0

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References

Related threats