Unrated severityNVD Advisory· Published Feb 27, 2026· Updated Mar 2, 2026
Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value
CVE-2026-25085
Description
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.
Affected products
4- Copeland/Copeland XWEB 300D PROv5Range: 0
- Copeland/Copeland XWEB 500B PROv5Range: 0
- Copeland/Copeland XWEB 500D PROv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.