Executive brief
CONPROSYS HMI System is an industrial human-machine interface used to control and monitor manufacturing and automation systems. An eval injection vulnerability allows authenticated attackers to execute arbitrary code on systems running vulnerable versions, potentially compromising production environments, stealing operational data, or disrupting critical industrial processes.
Technical details
CVE-2026-82789 is an improper neutralization of directives in dynamically evaluated code (eval injection, CWE-95) in CONPROSYS HMI System. The vulnerability requires authentication (PR:L) and can be exploited over the network (AV:N) without user interaction. An authenticated attacker can inject and execute arbitrary code with high impact on confidentiality, integrity, and availability. The attack vector is network-based and precondition is valid login credentials to the HMI System. Patches are available in version 3.8.0 and later.
Affected products
- Contec CONPROSYS HMI System prior to 3.8.0
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory