Executive brief
Contec CONPROSYS PAC Series is an industrial automation product used in manufacturing and process control environments. A flaw in the product allows unauthenticated remote attackers to access directory listings through a specific URL, potentially exposing sensitive file paths, configuration details, and other operational information that could be used to plan further attacks.
Technical details
CVE-2026-82778 is an exposure of information through directory listing vulnerability (CWE-548) in CONPROSYS PAC Series. The vulnerability allows a remote unauthenticated attacker to enumerate directories and access directory listings without authentication by accessing a specific URL on the product. The attack requires only network access with no authentication or special preconditions. An attacker can obtain sensitive directory information that may disclose file names, paths, and system configuration. Patches are available in version 3.0.0 and later for both the Integrated Type (CPS-PC341-*-9201) and Configurable type (CPS-PCS341-DS1-1201) products.
Affected products
- Contec CONPROSYS PAC Series prior to 3.0.0
Timeline
- 2026-09-14: disclosed
- 2026-09-10: advisory: JVNVU#96551518 published