Back to search
CVE-2026-41315
Published: May 14, 2026
Modified: May 16, 2026
PUBLISHED
Description
mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE.
| Vendor | Product | Versions |
|---|---|---|
midoks | mdserver-web | affected >= 0.18.0, <= 0.18.4 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now