CVE-2026-82789

Summary

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

Affected Software

VendorProductVersion RangeStatus
ContecCONPROSYS HMI System(CHS)0 < 3.8.0affected

Weaknesses

  • CWE-95: Improper neutralization of directives in dynamically evaluated code ('Eval Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References