CVE-2026-50980: XSS
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
oPanel deployments using a version before 1.20.25 are affected, specifically through the DNS lookup/management component.
What does an attacker need to exploit it?
The attacker needs to supply a crafted DNS TXT record that is processed by the vulnerable oPanel DNS lookup or management functionality. The issue can be exploited remotely.
What is the impact of successful exploitation?
A successful attack can execute arbitrary JavaScript in the affected context and may enable session hijacking.
What version addresses the vulnerability?
The vulnerability affects oPanel versions before 1.20.25; upgrading to version 1.20.25 or later addresses the affected version range described.