CVE-2026-50980 is a cross-site scripting vulnerability in the DNS lookup/management component of oPanel before version 1.20.25. Insufficient handling of attacker-controlled DNS TXT record content permits injected JavaScript to execute in the browser of a user who views the affected DNS data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained exploit PoC for CVE-2026-50980 affecting oPanel versions prior to 1.20.25. It contains two files: a README describing the vulnerability and attack scenario, and a single Python exploit script (exploit.py) that implements the attacker infrastructure. The exploit does not attack oPanel directly over HTTP; instead, it weaponizes the vulnerable DNS-processing workflow. The Python script starts two concurrent services: (1) a rogue UDP DNS server that answers incoming TXT queries with a malicious JavaScript payload and also returns an A record pointing to the attacker IP, and (2) a TCP HTTP listener that waits for the victim browser to request /log?cookie=... after the XSS executes. The payload is hardcoded as a script tag using new Image().src to exfiltrate document.cookie. Code structure is straightforward: DNSExploit.__init__ builds the payload string from user-supplied IP and ports; print_banner displays runtime configuration; dns_server binds to 0.0.0.0 on the chosen DNS port and responds to every query with malicious TXT/A records using dnslib; http_listener binds to 0.0.0.0 on the chosen HTTP port, parses inbound GET requests with a regex for cookie=... HTTP, and prints stolen cookies; run launches both services in daemon threads and keeps the process alive. The script is invoked from the command line with required attacker IP and optional HTTP/DNS ports. Overall purpose: provide an operational proof-of-concept for DNS-based XSS leading to session hijacking in oPanel by supplying attacker-controlled DNS answers and collecting the resulting stolen session cookies.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.