---
id: CVE-2026-82789
title: >-
  An improper neutralization of directives in dynamically evaluated code ('Eval
  Injection') issue exists in CONPROSYS HMI System(CHS)
summary: >-
  An improper neutralization of directives in dynamically evaluated code ('Eval
  Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary
  code may be executed by an attacker who can log in to the product.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-95
vendor: Contec
product: CONPROSYS HMI System(CHS)
affected:
  - conprosys_hmi_system_chs < 3.8.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82789'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU96551518/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_cps_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.00549
epssPercentile: 0.43589
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T15:38:44.904489Z'
ingestedAt: '2026-09-14T15:23:07.464Z'
---

## Overview

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
