216.73.217.22

CVE-2026-41315

· Published 14/05/2026 19:16 · Modified 15/05/2026 14:55

Labels: CVE-2026-41315 2026-05-14CVE-2026-41315CWE-78[email protected]

Essential information

Published
14/05/2026 19:16
Modified
15/05/2026 14:55
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start them, achieving RCE.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mdserver / mdserver-web cpe:2.3:a:mdserver:mdserver-web:0.18.0-0.18.4:*:*:*:*:*:*:*

References