CVE-2026-3037

8.0

Copeland · XWEB Pro (300D, 500D, 500B)

An OS command injection vulnerability in Copeland XWEB Pro (versions 1.12.1 and prior) allows an authenticated attacker to execute arbitrary code via the MBird SMS service utility route.

Executive summary

An OS command injection vulnerability in Copeland XWEB Pro systems allows an authenticated attacker to achieve remote code execution, posing a severe risk to system integrity and availability.

Vulnerability

This vulnerability is an OS command injection flaw (CWE-78) triggered by injecting malicious input into the MBird SMS service URL or utility route. Exploitation requires the attacker to be an authenticated user with high privileges.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected XWEB Pro system, leading to potential data compromise, unauthorized configuration changes, and total service disruption. With a CVSS score of 8.0, this high-severity flaw represents a significant risk to operational technology environments, where unauthorized command execution could result in physical process instability or safety concerns.

Remediation

Immediate Action: Update XWEB Pro to the latest version via the official Copeland software update page or by navigating to the SYSTEM, Updates, Network menu if the unit has internet access.

Proactive Monitoring: Monitor system logs for unauthorized access or suspicious activity originating from the MBird SMS service or utility route functions.

Compensating Controls: Restrict administrative network access to the XWEB Pro interface to trusted management subnets only, and implement network segmentation to isolate these controllers from general corporate traffic.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, organizations should prioritize patching all affected XWEB Pro units immediately. Administrators must ensure that only authorized personnel have high-level access to the system to prevent the conditions necessary for this exploit from being met.

More Copeland CVEs

Sources

Originally found and disclosed by Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.