A command injection vulnerability has been identified in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier. Authenticated attackers can exploit the 'url' parameter to execute arbitrary shell commands on the affected system. The vulnerability requires authentication, but once an attacker has valid credentials, they can achieve remote code execution. This affects all versions of oPanel up to and including v1.19.50. The issue has been assigned CVE-2026-50979 and is tracked by NVD. A proof-of-concept has been published on GitHub by bugresearch. The vulnerability poses a significant risk to server environments where oPanel is deployed as a hosting control panel.