CVE-2026-22877

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 
and prior, enabling unauthenticated attackers to read arbitrary files on
 the system, and potentially causing a denial-of-service attack.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
icscertCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N