LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-21718

CVE-2026-21718 - Vulnerability Analysis

CriticalCVSS: 10.0

Last Updated: February 27, 2026

Copeland XWEB Pro - Authentication Bypass

Published: February 27, 2026Updated: February 27, 2026Remote Exploitable

Overview

Copeland XWEB Pro <= 1.12.1 contains an authentication bypass vulnerability caused by improper authentication checks, letting attackers bypass authentication and execute code pre-authentication.

Severity & Score

Severity: Critical
CVSS Score: 10.0
EPSS Score: 6.8%(Probability of exploitation in next 30 days)

Impact

Attackers can bypass authentication and execute code without prior access, potentially compromising the entire system.

Mitigation

Update to the latest version beyond 1.12.1.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Feb 27, 2026

šŸ”“ CVE-2026-21718 - Critical (10) An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-21718/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-21718
Severity
Critical
CVSS Score
10.0
Type
broken_authentication
Status
confirmed
EPSS
6.8%
Social Posts
1

CWE

  • CWE-327
  • NVD-CWE-noinfo

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Score

6.8%Probability of exploitation in the next 30 days