Junglewise Threat Intelligence

CVE-2026-82795: Contec SolarView Compact cross-site scripting in Schedule Settings

CVE-2026-82795 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Vendors: Contec.

Executive brief

SolarView Compact is an industrial monitoring and control system used to manage renewable energy installations. The product contains a cross-site scripting (XSS) vulnerability in its Schedule Settings and Mail Send Settings that could allow a logged-in attacker to execute arbitrary scripts in other users' browsers, potentially leading to unauthorized configuration changes or data theft.

Technical details

The vulnerability is a stored/reflected cross-site scripting (CWE-79) flaw in the Schedule Settings and Mail Send Setting components of SolarView Compact. It requires an authenticated user (PR:L) and user interaction (UI:R) to exploit, meaning an attacker must convince a logged-in user to visit a malicious link or submit crafted input. When exploited, arbitrary JavaScript can execute in the victim's browser within the SolarView Compact web interface context, potentially allowing session hijacking or unauthorized actions. The vulnerability affects SolarView Compact versions prior to 9.00 (SV-CPT-MC310 and SV-CPT-MC310F). A firmware update to version 9.00 or later is available to remediate the issue.

Affected products

  • Contec SolarView Compact SV-CPT-MC310 and SV-CPT-MC310F prior to 9.00

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory

References