---
id: CVE-2026-82766
title: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in SGA1000
summary: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in SGA1000. If this vulnerability is exploited, an
  arbitrary OS command may be executed by an attacker who can log in to the
  product.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: 'Contec Co., Ltd.'
product: SGA1000
affected:
  - SGA1000 < 1.02
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82766'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU99009004/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_fl_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.01868
epssPercentile: 0.78427
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T11:09:17.653335Z'
ingestedAt: '2026-09-14T15:23:07.461Z'
---

## Overview

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
