CVE-2026-82776: Medium severity CONPROSYS PAC Series vulnerability
Published Sep 14, 2026
·Updated
Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Affected Software
1 affected component
CONPROSYS PAC Series
Event History
Sep 14, 2026
CVE Published
via MITRE·06:39 AM
Data Sourced
via MITRE·06:39 AM
DescriptionSeverity
Frequently Asked Questions
1
Does an attacker need an account on the affected system to attempt exploitation?
No. The CVSS vector indicates network reachability and no attacker privileges are required, but user interaction is required and the target user must be logged in.
2
What is the expected impact if exploitation succeeds?
The listed impact is low confidentiality and integrity impact, with no availability impact. The CVSS vector also indicates that the impact occurs across a changed security scope.