PatchSiren cyber security CVE debrief
CVE-2026-22877 Copeland CVE debrief
CVE-2026-22877 is an unauthenticated, network-reachable arbitrary file-read vulnerability in Copeland XWEB Pro version 1.12.1 and earlier. The advisory says affected systems may expose arbitrary local files and could also be driven into a denial-of-service condition, so this is primarily a confidentiality exposure with some operational risk.
- Vendor
- Copeland
- Product
- XWEB 300D PRO
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
Administrators and operators of Copeland XWEB Pro deployments, especially the XWEB 300D PRO, XWEB 500D PRO, and XWEB 500B PRO model families named in the advisory, along with OT/ICS teams responsible for patching and access control.
Technical summary
The supplied CISA CSAF advisory (ICSA-26-057-10) describes CVE-2026-22877 as an arbitrary file-read flaw in XWEB Pro 1.12.1 and prior that can be exercised without authentication. The provided CVSS vector is AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N, which scores the issue as low severity, with limited confidentiality impact and no integrity or availability impact reflected in the vector; the narrative note also mentions potential denial of service.
Defensive priority
Patch promptly, but this is not a KEV-class emergency in the supplied data. Prioritize any deployments that are broadly network reachable, and move affected systems onto the next available maintenance window if exposure is limited.
Recommended defensive actions
- Update XWEB Pro to the latest vendor-fixed version using Copeland's software update page referenced in the advisory.
- If the device has internet access and a logged-in operator, use the SYSTEM -- Updates | Network menu to retrieve the fix directly from Copeland.
- Inventory XWEB Pro installations and confirm whether any device is running version 1.12.1 or earlier.
- Follow CISA ICS recommended practices while patching and reducing exposure for affected OT/ICS systems.
Evidence notes
This debrief is based on the supplied CISA CSAF source item for ICSA-26-057-10, published and modified on 2026-02-26. The advisory text states that XWEB Pro version 1.12.1 and prior is affected by an unauthenticated arbitrary file-read issue with possible denial-of-service impact, and it provides remediation guidance to update via Copeland's software update page or the device's network update function. The supplied enrichment data does not list the CVE in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-22877 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-22877
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-22877 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22877
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.