Junglewise Threat Intelligence

CVE-2026-50979: Osbil Technology oPanel command injection in advanced/curl

CVE-2026-50979 · Severity: high · CVSS 8.1 · Published 2026-08-28

Executive brief

Osbil Technology oPanel is a control panel software used to manage web hosting and server resources. A command injection vulnerability in the advanced/curl component allows authenticated users to execute arbitrary shell commands on the server, potentially compromising the entire hosting environment and any customer sites or data hosted on that server.

Technical details

This is a command injection vulnerability in the 'advanced/curl' component of oPanel that allows authenticated attackers to execute arbitrary shell commands. The vulnerability exists in the handling of the 'url' parameter, which is not properly sanitized before being used in shell operations. An authenticated attacker can craft a malicious URL parameter containing shell metacharacters to break out of the intended command context and execute arbitrary commands with the privileges of the web server process. The vulnerability affects oPanel v1.19.50 and earlier versions. Patching to a version later than v1.19.50 is required to remediate this issue.

Affected products

  • Osbil Technology oPanel v1.19.50 and earlier

Timeline

  • 2026-08-28: disclosed

References