An OS command injection
vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an
authenticated attacker to achieve remote code execution on the system by
sending malicious input injected into the server username field of the
import preconfiguration action in the API V1 route.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route. | |
| Title | Copeland XWEB and XWEB Pro OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-02-27T00:54:21.133Z
Reserved: 2026-02-05T16:47:16.546Z
Link: CVE-2026-23702
No data.
Status : Received
Published: 2026-02-27T02:16:18.700
Modified: 2026-02-27T02:16:18.700
Link: CVE-2026-23702
No data.
OpenCVE Enrichment
No data.