Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-57517: Control Web Panel before 0.9.8.1225 allows remote code execution
CVE-2026-57517
Summary
An attacker can inject malicious code into Control Web Panel, allowing them to execute arbitrary commands on the server. This can happen if you're running an outdated version of the software. To protect yourself, update to version 0.9.8.1225 or later.
Original title
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input throug...
Original description
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-89
SQL Injection
Published: 1 Jul 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026