CVE-2026-50979: Command Injection
Published Aug 28, 2026
·Updated
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
Affected Software
2 affected components
Osbil Technology oPanel<=1.19.50
advanced/curl
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must be authenticated to oPanel and able to access the advanced/curl component. The provided information does not indicate that unauthenticated users can exploit it.
2
Which versions are affected?
oPanel version 1.19.50 and earlier are affected.
3
What input is used to trigger the command injection?
The issue is triggered through the url parameter in the advanced/curl component. Successful exploitation allows execution of arbitrary shell commands.