---
id: CVE-2026-82795
title: >-
  SolarView Compact contains a cross-site scripting vulnerability in Schedule
  Settings and Mail Send Setting
summary: >-
  SolarView Compact contains a cross-site scripting vulnerability in Schedule
  Settings and Mail Send Setting. If this vulnerability is exploited, an
  arbitrary OS command may be executed by an attacker who can log in to the
  product.
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: 'Contec Co., Ltd.'
product: SV-CPT-MC310
affected:
  - SV-CPT-MC310 < 9.00
  - SV-CPT-MC310F < 9.00
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:27:25.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82795'
references:
  - url: 'https://jvn.jp/en/vu/JVNVU97753461/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.contec.com/api/downloadlogger?download=/-/media/Contec/support/security-info/2026/contec_security_sv_26091000_en.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.00237
epssPercentile: 0.13147
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T14:42:51.966764Z'
ingestedAt: '2026-09-14T15:23:07.420Z'
---

## Overview

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
