Vulnerability Description
mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Midoks | Mdserver-Web | >= 0.18.0, <= 0.18.4 |
Related Weaknesses (CWE)
References
- https://github.com/midoks/mdserver-web/security/advisories/GHSA-3h92-g9hr-xc25ExploitVendor Advisory
- https://github.com/midoks/mdserver-web/security/advisories/GHSA-3h92-g9hr-xc25ExploitVendor Advisory
FAQ
What is CVE-2026-41315?
CVE-2026-41315 is a vulnerability with a CVSS score of 9.8 (CRITICAL). mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond an...
How severe is CVE-2026-41315?
CVE-2026-41315 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-41315?
Check the references section above for vendor advisories and patch information. Affected products include: Midoks Mdserver-Web.