Junglewise Threat Intelligence

CVE-2026-82794: Contec SolarView Compact OS command injection in Schedule Settings

CVE-2026-82794 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Contec.

Executive brief

SolarView Compact is an industrial monitoring and control system used by organizations to manage solar power installations and related equipment. An OS command injection vulnerability in the Schedule Settings component allows authenticated attackers to execute arbitrary system commands on the device, potentially leading to full system compromise, data theft, or disruption of power generation monitoring and control operations.

Technical details

SolarView Compact contains an OS command injection vulnerability (CWE-78) in the Schedule Settings feature. The vulnerability requires authenticated access (login credentials) but does not require user interaction. An attacker with valid login credentials can inject arbitrary OS commands that will be executed with the privileges of the application, allowing arbitrary code execution on the underlying system. The CVSS 3.1 score of 8.8 reflects high impact on confidentiality, integrity, and availability. A firmware patch to version 9.00 or later is available from the vendor.

Affected products

  • Contec SolarView Compact SV-CPT-MC310 prior to 9.00
  • Contec SolarView Compact SV-CPT-MC310F prior to 9.00

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: Firmware version 9.00 or later available

References

Related threats