CVE-2026-21389 | Copeland XWEB 300D PRO/XWEB 500D PRO/XWEB 500B PRO up to 1.12.1 Request Body os command injection
A vulnerability labeled as critical has been found in Copeland XWEB 300D PRO, XWEB 500D PRO and XWEB 500B PRO up to 1.12.1. This affects an unknown function of the component Request Body Handler. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-21389. The attack can be launched remotely. No exploit exists.