CVE-2026-20902
8.0Copeland · XWEB Pro
An OS command injection vulnerability in Copeland XWEB Pro allows an authenticated attacker to achieve remote code execution via malicious input in the map filename field.
Executive summary
A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to gain remote code execution, posing a severe risk of total system compromise.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) occurring in the map filename field during the map upload action of the parameters route. Successful exploitation requires an attacker to have authenticated access to the system.
Business impact
The ability to execute arbitrary OS commands leads to a complete loss of confidentiality, integrity, and availability of the affected XWEB Pro units. Given the CVSS score of 8.0, this high severity flaw could result in unauthorized administrative access, potential lateral movement within the industrial control environment, and significant operational downtime.
Remediation
Immediate Action: Update the XWEB Pro firmware to the latest version via the official Copeland software update page or through the device's internal system update menu.
Proactive Monitoring: Review system access logs for unauthorized changes to parameters or unusual activity during file upload processes.
Compensating Controls: Restrict network access to the XWEB Pro web interface to trusted administrative IP addresses only to reduce the attack surface for authenticated users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Copeland XWEB Pro administrators must prioritize applying the provided firmware updates to all affected units. Because this flaw enables remote code execution with high privileges, failure to patch could lead to full system takeover. Organizations should verify their current firmware version immediately and schedule maintenance windows to perform the necessary upgrades.
More Copeland CVEs
Sources
Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.