PT-2026-22261 · Xweb Pro · Xweb Pro

Amir Zaltzman

+1

·

Published

2026-02-27

·

Updated

2026-03-10

·

CVE-2026-25111

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWEB Pro versions prior to 1.12.1
Description An OS command injection issue exists that allows a logged-in attacker to execute code remotely on the system. This is achieved by submitting crafted input to the restore route. The restore route is susceptible to command injection due to improper input validation. The vulnerable parameter is not specified.
Recommendations Update XWEB Pro to a version later than 1.12.1.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25111

Affected Products

Xweb Pro