CVE-2026-24452

8.0

Copeland · XWEB PRO

A critical OS command injection vulnerability in Copeland XWEB PRO devices allows authenticated users to execute arbitrary code by uploading a crafted template file to the devices route.

Executive summary

A critical OS command injection vulnerability in Copeland XWEB PRO models allows an authenticated attacker to achieve remote code execution, potentially leading to full system compromise.

Vulnerability

This vulnerability is an OS command injection (CWE-78) occurring within the template file processing logic of the XWEB PRO interface. It requires the attacker to have authenticated access to the system to submit a malicious file to the device route, which then executes the injected commands with system-level privileges.

Business impact

The ability to achieve remote code execution poses a severe risk to operational technology environments where these devices are deployed. Successful exploitation allows an attacker to gain full control over the affected hardware, potentially leading to unauthorized data access, disruption of critical monitoring functions, or lateral movement into broader facility networks. With a CVSS score of 8.0, this high-severity flaw requires immediate attention to prevent operational downtime and potential safety risks.

Remediation

Immediate Action: Update your XWEB PRO devices to the latest software version by visiting the official Copeland software update page or by initiating an update directly through the System, Updates, Network menu on the device.

Proactive Monitoring: Review system logs for unauthorized file uploads or unusual command executions, particularly those originating from administrative user accounts.

Compensating Controls: Restrict network access to the XWEB PRO management interface to trusted administrative subnets only, and ensure that all user accounts are protected by strong, unique credentials to limit the risk of unauthorized authentication.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise, administrators must prioritize patching these devices immediately. Ensure that the update process is performed through verified channels provided by Copeland and audit existing user access controls to minimize the attack surface for this vulnerability.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.