PatchSiren cyber security CVE debrief
CVE-2026-20902 Copeland CVE debrief
CISA’s 2026-02-26 advisory (ICSA-26-057-10) says XWEB Pro version 1.12.1 and prior contains an OS command injection issue in the map upload workflow. An authenticated attacker can inject malicious input into the map filename field on the parameters route and achieve remote code execution on the system. Copeland provides a fix and recommends updating affected XWEB Pro deployments to the latest version.
- Vendor
- Copeland
- Product
- XWEB 300D PRO
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
Administrators and operators responsible for Copeland XWEB Pro deployments, especially XWEB 300D PRO, XWEB 500D PRO, and XWEB 500B PRO systems. This matters most where authenticated users can reach the management interface or where the device is exposed to broader enterprise or remote-access networks.
Technical summary
The advisory describes a command-injection weakness in the map upload action, specifically in the map filename field on the parameters route. Exploitation requires an authenticated attacker and no user interaction, but successful abuse can lead to remote code execution with high confidentiality, integrity, and availability impact. The supplied CVSS vector reflects network reachability, high attack complexity, and high privileges required: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H.
Defensive priority
High. Patch promptly, with special attention to internet-accessible or remotely administered instances.
Recommended defensive actions
- Update XWEB Pro to the latest vendor-released version using Copeland’s software update path.
- If using direct device updates, verify the target is approved for online update before using SYSTEM → Updates → Network.
- Restrict authenticated access to the XWEB Pro management interface to trusted administrative networks only.
- Review logs and account activity for unusual requests to the parameters route or map upload functions.
- Confirm all deployed instances and versions against the advisory, including XWEB 300D PRO, XWEB 500D PRO, and XWEB 500B PRO.
Evidence notes
Primary evidence comes from the CISA CSAF advisory ICSA-26-057-10, published 2026-02-26 UTC, which states that XWEB Pro version 1.12.1 and prior is vulnerable to OS command injection via the map filename field during the map upload action of the parameters route. The supplied advisory metadata also includes the CVSS v3.1 vector AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H and points to Copeland’s software update page as the remediation path. No exploitation activity or KEV listing is included in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20902 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20902
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20902 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20902
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.