CVE-2026-57517 Details
Description
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.
A blind SQL injection vulnerability has been identified in Control Web Panel (CWP) versions prior to 0.9.8.1225. This vulnerability allows unauthenticated remote attackers to execute arbitrary SQL queries by sending unsanitized input through the userRes POST parameter at the user endpoint. Exploitation of this vulnerability is possible if the attacker knows or correctly guesses the username of a valid non-root account on the affected CWP instance. Successful exploitation grants access to the MySQL root privileges, which can be used to write arbitrary files into accessible locations on the server. This capability could be leveraged to deploy a PHP web shell in the Roundcube logs directory, resulting in remote code execution on the server as the cwpsvc account.
Users are advised to upgrade to Control Web Panel version 0.9.8.1225 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CVE |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |