CVE-2026-82779: Command Injection
Published Sep 14, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Affected Software
1 affected component
CONPROSYS TM Series
Event History
Sep 14, 2026
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be able to log in to the CONPROSYS TM Series product. No user interaction is required after the attacker has authenticated.
2
What could an attacker do if exploitation succeeds?
A successful exploit can allow execution of arbitrary OS commands. This may affect the confidentiality, integrity, and availability of the affected system.