PT-2026-22256 · Xweb Pro · Xweb Pro

Amir Zaltzman

+1

·

Published

2026-02-27

·

Updated

2026-05-06

·

CVE-2026-24663

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWEB Pro versions prior to 1.12.1
Description An unauthenticated attacker can execute commands on the system remotely. This is possible by sending a specially crafted request to the libraries installation route and injecting malicious input into the request body. The application improperly processes requests, allowing for remote code execution (RCE).
Recommendations Versions prior to 1.12.1 should be updated.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-24663

Affected Products

Xweb Pro