CVE-2026-21389

8.0

Copeland · XWEB Pro

An OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to execute arbitrary code via the contacts import route.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution, posing a significant risk to system integrity.

Vulnerability

This vulnerability is a classic OS command injection (CWE-78) flaw triggered by injecting malicious input into the request body of the contacts import route. The vulnerability requires the attacker to be authenticated to the system.

Business impact

The ability to execute arbitrary OS commands provides an attacker with total control over the affected XWEB Pro device. Given the CVSS score of 8.0, this high severity vulnerability could lead to complete system compromise, unauthorized access to sensitive operational data, and potential lateral movement within the industrial control environment.

Remediation

Immediate Action: Update XWEB Pro to the latest available version via the official Copeland software update portal or directly through the device menu under SYSTEM, Updates, Network.

Proactive Monitoring: Review system access logs for unusual activity surrounding the contacts import functionality and monitor for unexpected outbound network connections initiated by the XWEB Pro device.

Compensating Controls: Ensure that access to the XWEB Pro interface is restricted to authorized personnel only via network segmentation and strict firewall policies to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of this command injection flaw, organizations should prioritize updating their XWEB Pro units immediately. Restricting administrative access to the device remains a critical secondary control while update deployment is coordinated across the environment.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.