---
id: CVE-2026-82777
title: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in CONPROSYS PAC Series
summary: >-
  Improper neutralization of special elements used in an OS command ('OS Command
  Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is
  exploited, an arbitrary OS command may be executed by an attacker who can log
  in to…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: 'Contec Co., Ltd.'
product: 'Integrated Type CPS-PC341[][]-*-9201'
affected:
  - integrated_type_cps-pc341_-_-9201 < 3.0.0
  - configurable_type_cps-pcs341_-ds1-1201 < 3.0.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82777'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU96551518/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.01868
epssPercentile: 0.78396
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T11:07:54.466979Z'
ingestedAt: '2026-09-14T15:23:07.461Z'
---

## Overview

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
