CVE-2026-25085CWE-394

Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value

High · published February 27, 2026

CVSS v3.1
8.6
EPSS
0%
Percentile
40.4
In the wild
Unconfirmed
What it is

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in

which an unexpected return value from the authentication routine is

later on processed as a legitimate value, resulting in an authentication

bypass.

The record
Technical detail
CVSS v3.1
8.6 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00490 · 40.4th percentile
Weakness
CWE-394 · Unexpected Status Code or Return Value
Published
2026-02-27T00:33Z
EPSS history
Timeline
  • 27 FEB 00:33Z
    Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value
    cvelistv5