CVE-2026-50979 is an OS command injection vulnerability in the advanced/curl component of Osbil Technology oPanel version 1.19.50 and earlier. The component insufficiently neutralizes attacker-controlled input supplied through its URL parameter before invoking shell functionality, allowing an authenticated user to inject and execute arbitrary shell commands in the context of the affected oPanel application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-50979, an authenticated command injection/RCE issue in oPanel v1.19.50 and earlier. The repo contains only two files: a README describing the vulnerability and exploitation concept, and exploit.py implementing the attack logic. The exploit workflow is straightforward: it accepts target hostname, username, password, and optionally a command. It builds a base URL of https://<target>:2083/, creates a requests session, and performs an authenticated POST to the application root using username/password form fields. After a successful HTTP 200 response, it sends a second POST to /advanced/curl with a crafted url parameter. The payload is constructed as http://example.com/;<command>, with spaces replaced by ${IFS} to bypass simple space filtering. This is intended to break out of the backend curl invocation and execute arbitrary shell commands. The script supports two modes: single-command execution via -c/--command, and an interactive loop that behaves like a basic remote shell by repeatedly prompting for commands and sending them to the vulnerable endpoint. Returned HTML is parsed with BeautifulSoup; the script attempts to extract command output from a <pre> tag and strips likely HTTP header noise if needed. Notable implementation details: SSL certificate verification is disabled, warnings are suppressed, and timeouts are set on requests. The exploit does not include advanced post-exploitation payload delivery, persistence, or lateral movement automation; it is an operational authenticated RCE tool with a hardcoded injection pattern rather than a generalized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.