# CVE-2026-82789

## Summary

- **CVE ID:** CVE-2026-82789
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-95
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

## Affected Products

- Contec — CONPROSYS HMI System(CHS) (0)

## References

- [CNA](https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf)
- [CNA](https://jvn.jp/en/vu/JVNVU96551518/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 23.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._