CVE-2026-82789
Received Received - Intake

Improper Eval Injection in CONPROSYS HMI System

Vulnerability report for CVE-2026-82789, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: JPCERT/CC

Description

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
conprosys conprosys_hmi_system *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper neutralization of directives in dynamically evaluated code (Eval Injection) vulnerability in CONPROSYS HMI System(CHS). It allows arbitrary code execution if an attacker can log in to the product.

Impact Analysis

An attacker with login access could execute arbitrary code on the system, potentially leading to unauthorized data access, system manipulation, or disruption of operations.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR (data protection) and HIPAA (health data security) requirements, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Immediately restrict access to the CONPROSYS HMI System to trusted users only. Apply vendor patches or updates if available. Monitor network traffic for unusual activity or unauthorized code execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82789. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart