ZeroHour

CVE-2026-50979

Authenticated Command Injection in Osbil Technology oPanel ≤ 1.19.50

CVSS 3.1
8.1 high
EPSS
1%p71
Published
()
Modified
AI analysis

Osbil Technology oPanel, a hosting control panel, contains a command injection flaw (CWE-77) in its 'advanced/curl' component. An authenticated attacker with a low-privilege account can supply a crafted value in the 'url' parameter, which the application passes unsafely to a shell, resulting in arbitrary command execution. Successful exploitation yields arbitrary shell command execution on the server under the web service user, which on a control-panel deployment can expose hosted sites, databases, and credentials. All deployments running oPanel version 1.19.50 or earlier are affected, and the network-adjacent attack requires only valid (low-privilege) credentials with no user interaction. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV, and exploitation is not known to be occurring in the wild, with EPSS estimating a 1.4% chance of exploitation within 30 days.

What to do: Upgrade oPanel to a fixed release newer than 1.19.50 as soon as the vendor publishes one, and verify your installed version via the panel's about/system page. Until patched, restrict 'advanced/curl' functionality to trusted, high-trust accounts, apply least privilege to the web service user's shell access, and monitor web logs for unexpected commands or arguments in the 'url' parameter. Watch the vendor's release notes and the CVE feed for a confirmed fixed version and any published proof-of-concept.

Affected
Osbil Technology oPanel≤ 1.19.50 (all versions through 1.19.50)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.