Junglewise Threat Intelligence

CVE-2026-82787: Contec CONPROSYS IO-Link Master missing authentication for critical function

CVE-2026-82787 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

The Contec CONPROSYS IO-Link Master (model CPSL-08P1EN) is an industrial device used to manage input/output data in manufacturing and automation environments. A missing authentication vulnerability allows remote attackers to execute REST API calls without logging in, potentially retrieving sensitive I/O values or controlling critical outputs without authorization.

Technical details

This is a missing authentication vulnerability (CWE-306) in the REST API of the CONPROSYS IO-Link Master CPSL-08P1EN versions prior to 2.3.10. The vulnerability allows unauthenticated network-based access to critical API endpoints that control and monitor industrial I/O operations. An attacker without credentials can interact with the REST API to read I/O values and manipulate output states, potentially disrupting industrial processes. The vulnerability requires no user interaction and is remotely exploitable over the network. Patches are available in version 2.3.10 and later.

Affected products

  • Contec CONPROSYS IO-Link Master CPSL-08P1EN prior to 2.3.10

Timeline

  • 2026-09-14: disclosed
  • 2026-09-10: advisory: JVNVU#96551518 published

References

Related threats