Junglewise Threat Intelligence

CVE-2026-82796: Contec SolarView Compact cross-site scripting in Image Management

CVE-2026-82796 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Vendors: Contec.

Executive brief

SolarView Compact is a monitoring and control application used to manage industrial equipment and systems. A cross-site scripting vulnerability in the Image Management feature allows attackers who are already logged in to the product to execute arbitrary scripts in the context of other users' browsers, potentially leading to account takeover or malicious actions within the system.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in the Image Management component of SolarView Compact. The vulnerability requires an authenticated attacker (login to the product is necessary) and user interaction (the target must click a malicious link or open a crafted page). Successful exploitation allows arbitrary JavaScript execution in the browser of a logged-in user, enabling session hijacking, credential theft, or malicious actions performed on behalf of the victim. The vulnerability is tracked as CVE-2026-82796 with a CVSS v3.1 score of 5.4. A firmware update to version 9.00 or later is available as a mitigation.

Affected products

  • Contec SolarView Compact SV-CPT-MC310 prior to 9.00
  • Contec SolarView Compact SV-CPT-MC310F prior to 9.00

Timeline

  • 2026-09-10: disclosed
  • 2026-09-14: advisory: CVE-2026-82796 published

References

Related threats