A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameterReferenceshttp://opanel.comhttp://osbil.comhttps://github.com/bugresearch/CVE-2026-50979