Executive brief
Osbil Technology oPanel is a control panel software used to manage web hosting and server resources. A command injection vulnerability in the advanced/curl component allows authenticated users to execute arbitrary shell commands on the server, potentially compromising the entire hosting environment and any customer sites or data hosted on that server.
Technical details
This is a command injection vulnerability in the 'advanced/curl' component of oPanel that allows authenticated attackers to execute arbitrary shell commands. The vulnerability exists in the handling of the 'url' parameter, which is not properly sanitized before being used in shell operations. An authenticated attacker can craft a malicious URL parameter containing shell metacharacters to break out of the intended command context and execute arbitrary commands with the privileges of the web server process. The vulnerability affects oPanel v1.19.50 and earlier versions. Patching to a version later than v1.19.50 is required to remediate this issue.
Affected products
- Osbil Technology oPanel v1.19.50 and earlier
Timeline
- 2026-08-28: disclosed