CVE-2026-20764

8.0

Copeland · XWEB Pro (300D, 500D, 500B)

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute arbitrary code via the device hostname configuration.

Executive summary

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution, posing a significant risk to system integrity and availability.

Vulnerability

This vulnerability (CWE-78) involves improper neutralization of special elements used in an OS command. It requires an authenticated attacker with high privileges to inject malicious input into the device hostname configuration field, which is subsequently executed by the system during the setup process.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary commands on the underlying operating system. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, and potential disruption of critical operational technology environments.

Remediation

Immediate Action: Update XWEB Pro devices to the latest available version by accessing the Copeland software update page or via the system menu (SYSTEM, Updates, Network) for internet-connected units.

Proactive Monitoring: Monitor system logs for unusual hostname changes or unexpected process executions that may indicate an attempt to leverage command injection vectors.

Compensating Controls: Restrict administrative access to the XWEB Pro management interface to authorized personnel only, and implement network segmentation to isolate these controllers from untrusted network segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing Copeland XWEB Pro controllers must prioritize the application of the vendor-supplied firmware update. Given the high-severity nature of command injection vulnerabilities, establishing a maintenance window to patch all affected devices is necessary to prevent potential unauthorized system control.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.