Vulnerability Description
mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE.
Related Weaknesses (CWE)
References
- https://github.com/midoks/mdserver-web/security/advisories/GHSA-3h92-g9hr-xc25
- https://github.com/midoks/mdserver-web/security/advisories/GHSA-3h92-g9hr-xc25
FAQ
What is CVE-2026-41315?
CVE-2026-41315 is a documented vulnerability. mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond an...
How severe is CVE-2026-41315?
CVSS scoring is not yet available for CVE-2026-41315. Check NVD for updates.
Is there a patch for CVE-2026-41315?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.