Junglewise Threat Intelligence

CVE-2026-82777: Contec CONPROSYS PAC OS command injection

CVE-2026-82777 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

Contec CONPROSYS PAC Series is an industrial programmable logic controller and gateway platform used to connect and manage field devices in manufacturing environments. A command injection vulnerability in authenticated sessions allows an attacker with valid login credentials to execute arbitrary system commands with full system privileges, potentially disrupting production operations or accessing sensitive industrial data.

Technical details

The vulnerability is an improper neutralization of special elements in OS command construction (CWE-78, OS Command Injection). The flaw exists in the CONPROSYS PAC Series and requires authentication—an attacker must have valid login credentials to exploit it. The vulnerability allows arbitrary OS command execution, which could lead to complete system compromise, data theft, or denial of service. Affected versions are: CONPROSYS PAC Integrated Type (CPS-PC341) prior to 3.0.0 and Configurable type (CPS-PCS341) prior to 3.0.0. Patched versions 3.0.0 and later have been released.

Affected products

  • Contec CONPROSYS PAC Integrated Type prior to 3.0.0
  • Contec CONPROSYS PAC Configurable Type prior to 3.0.0

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References