CVE Feed

    Dashboard / CVE / CVE-2026-57517

    CVE-2026-57517

    Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.

    Published:Jul 1, 2026
    Last Modified:Jul 1, 2026
    EPS:Jul 1, 2026
    EPSS Score:
    CVSS Score:9.8

    Affected Products

    Vendor
    Control Web Panel
    Product
    Control Web Panel

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High