Executive brief
SolarView Compact is a monitoring and control application used to manage industrial equipment and systems. A cross-site scripting vulnerability in the Image Management feature allows attackers who are already logged in to the product to execute arbitrary scripts in the context of other users' browsers, potentially leading to account takeover or malicious actions within the system.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability in the Image Management component of SolarView Compact. The vulnerability requires an authenticated attacker (login to the product is necessary) and user interaction (the target must click a malicious link or open a crafted page). Successful exploitation allows arbitrary JavaScript execution in the browser of a logged-in user, enabling session hijacking, credential theft, or malicious actions performed on behalf of the victim. The vulnerability is tracked as CVE-2026-82796 with a CVSS v3.1 score of 5.4. A firmware update to version 9.00 or later is available as a mitigation.
Affected products
- Contec SolarView Compact SV-CPT-MC310 prior to 9.00
- Contec SolarView Compact SV-CPT-MC310F prior to 9.00
Timeline
- 2026-09-10: disclosed
- 2026-09-14: advisory: CVE-2026-82796 published