top of page
perceptive_background_267k.jpg

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arb…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A command injection vulnerability has been identified in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier. Authenticated attackers can exploit the 'url' parameter to execute arbitrary shell commands on the affected system. The vulnerability requires authentication, but once an attacker has valid credentials, they can achieve remote code execution. This affects all versions of oPanel up to and including v1.19.50. The issue has been assigned CVE-2026-50979 and is tracked by NVD. A proof-of-concept has been published on GitHub by bugresearch. The vulnerability poses a significant risk to server environments where oPanel is deployed as a hosting control panel.

Technical details

Mitigation steps:

Affected products:

Osbil Technology oPanel v1.19.50

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page