Description
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
Published: 2026-08-28
Score: 8.1 High
EPSS: 1.4% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a command injection flaw (CWE-77) in the advanced/curl component of Osbil Technology oPanel v1.19.50 and earlier. The flaw allows an authenticated attacker to supply a malicious URL that is executed as a shell command, giving the attacker full control of the server’s operating system.

Affected Systems

This vulnerability affects Osbil Technology oPanel version 1.19.50 and any earlier releases, with the advanced/curl module processing the supplied ‘url’ parameter.

Risk and Exploitability

The CVSS score of 8.1 indicates a high level of risk. The EPSS score of 1% suggests a low to moderate probability of exploitation, though it is not listed in CISA’s KEV catalog. Once valid credentials are obtained, an attacker can execute arbitrary shell commands, making the impact potentially catastrophic. The likely attack vector is an authenticated web request to advanced/curl that manipulates the url parameter.

Generated by OpenCVE AI on August 29, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch – upgrade Osbil oPanel to v1.19.51 or later, when available.
  • Disable the advanced/curl feature or remove the endpoint so that the url parameter can no longer trigger command execution.
  • Limit administrative privileges so that only trusted users can access the advanced/curl functionality and monitor those accounts for suspicious activity.

Generated by OpenCVE AI on August 29, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Osbil
Osbil opanel
Vendors & Products Osbil
Osbil opanel

Sat, 29 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Command Injection in Osbil oPanel Advanced/Curl Module Allows Arbitrary Shell Execution

Sat, 29 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Fri, 28 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Shell Command Execution via URL Parameter in Osbil oPanel

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Shell Command Execution via URL Parameter in Osbil oPanel
Weaknesses CWE-78

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T19:25:55.492Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50979

cve-icon Vulnrichment

Updated: 2026-08-28T19:25:47.930Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:14.037

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-50979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:22:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')