CVE-2026-23702

8.0

Copeland · XWEB Pro

An OS command injection vulnerability exists in XWEB Pro versions 1.12.1 and prior, allowing authenticated attackers to execute arbitrary commands via the API V1 route.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB Pro allows authenticated attackers to achieve remote code execution on affected systems.

Vulnerability

This vulnerability is caused by improper neutralization of special elements used in an OS command (CWE-78). An authenticated attacker can trigger remote code execution by injecting malicious input into the server username field of the import preconfiguration action within the API V1 route.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected XWEB Pro device. Given the CVSS score of 8.0, this represents a high risk, as it could lead to the compromise of sensitive operational data, unauthorized manipulation of connected equipment, and potential system-wide disruption within an industrial environment.

Remediation

Immediate Action: Update the XWEB Pro software to the latest version by visiting the official Copeland software update page or by navigating to the SYSTEM, Updates, Network menu directly on the device.

Proactive Monitoring: Review system access logs for unusual activity associated with the API V1 endpoint and monitor for unauthorized changes to device configurations.

Compensating Controls: Ensure the XWEB Pro interface is not exposed to the public internet and restrict administrative access to trusted management networks only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this command injection flaw necessitates immediate attention. Administrators should prioritize patching all identified XWEB Pro units to the latest firmware version to eliminate the risk of remote code execution. Maintaining strict access control policies for the management interface is essential to preventing unauthorized users from triggering this vulnerability.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.