CVE-2026-25085CWE-394
Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value
High · published February 27, 2026
What it is
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in
which an unexpected return value from the authentication routine is
later on processed as a legitimate value, resulting in an authentication
bypass.
The record
Technical detail
- CVSS v3.1
- 8.6 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- CVSS v4.0
- Not supplied
- EPSS
- 0.00490 · 40.4th percentile
- Weakness
- CWE-394 · Unexpected Status Code or Return Value
- Published
- 2026-02-27T00:33Z
EPSS history
Timeline