CVE-2026-23702

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:copeland:xweb_300d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_300d_pro:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:copeland:xweb_500d_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500d_pro:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:copeland:xweb_500b_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:copeland:xweb_500b_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-27 02:16

Updated : 2026-02-27 23:08


NVD link : CVE-2026-23702

Mitre link : CVE-2026-23702

CVE.ORG link : CVE-2026-23702


JSON object : View

Products Affected

copeland

  • xweb_300d_pro
  • xweb_300d_pro_firmware
  • xweb_500b_pro_firmware
  • xweb_500b_pro
  • xweb_500d_pro_firmware
  • xweb_500d_pro
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')