


Perceptive Security
SOC/SIEM Consultancy

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arb…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 23:18:32
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A command injection vulnerability has been identified in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier. Authenticated attackers can exploit the 'url' parameter to execute arbitrary shell commands on the affected system. The vulnerability requires authentication, but once an attacker has valid credentials, they can achieve remote code execution. This affects all versions of oPanel up to and including v1.19.50. The issue has been assigned CVE-2026-50979 and is tracked by NVD. A proof-of-concept has been published on GitHub by bugresearch. The vulnerability poses a significant risk to server environments where oPanel is deployed as a hosting control panel.
Technical details
Mitigation steps:
Affected products:
Osbil Technology oPanel v1.19.50
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-50979
http://opanel.com
http://osbil.com
https://github.com/bugresearch/CVE-2026-50979
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
