Copeland XWEB Pro Authentication Bypass Vulnerability Allowing Pre-Authenticated Code Execution

Vulnerability

An authentication bypass vulnerability has been identified in Copeland XWEB Pro versions through 1.12.1. This vulnerability allows attackers to bypass authentication requirements and execute arbitrary code on the affected system without prior authentication.

Impact

Exploitation of this vulnerability could lead to unauthorized authentication bypass and pre-authenticated arbitrary code execution on the affected system.

Remediation

Copeland has released a patch for this vulnerability. Users are advised to update XWEB Pro to the latest version available. Instructions for updating can be found on the Copeland Software Update page, or users can update directly from Copeland servers via the SYSTEM -- Updates | Network menu.

Added: Feb 27, 2026, 1:26 AM
Updated: Feb 27, 2026, 1:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
3.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.