CVE-2026-50979
—Authenticated Command Injection in Osbil Technology oPanel ≤ 1.19.50
Osbil Technology oPanel, a hosting control panel, contains a command injection flaw (CWE-77) in its 'advanced/curl' component. An authenticated attacker with a low-privilege account can supply a crafted value in the 'url' parameter, which the application passes unsafely to a shell, resulting in arbitrary command execution. Successful exploitation yields arbitrary shell command execution on the server under the web service user, which on a control-panel deployment can expose hosted sites, databases, and credentials. All deployments running oPanel version 1.19.50 or earlier are affected, and the network-adjacent attack requires only valid (low-privilege) credentials with no user interaction. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV, and exploitation is not known to be occurring in the wild, with EPSS estimating a 1.4% chance of exploitation within 30 days.
What to do: Upgrade oPanel to a fixed release newer than 1.19.50 as soon as the vendor publishes one, and verify your installed version via the panel's about/system page. Until patched, restrict 'advanced/curl' functionality to trusted, high-trust accounts, apply least privilege to the web service user's shell access, and monitor web logs for unexpected commands or arguments in the 'url' parameter. Watch the vendor's release notes and the CVE feed for a confirmed fixed version and any published proof-of-concept.
| Osbil Technology oPanel | ≤ 1.19.50 (all versions through 1.19.50) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.