Executive brief
Control Web Panel, a server management interface for system administrators, contains a critical security flaw. An unauthenticated attacker can remotely execute commands on the server by sending specially crafted data to the user login endpoint. This could lead to a complete takeover of the server, unauthorized access to customer data, and full disruption of hosted services.
Technical details
A blind SQL injection vulnerability exists in Control Web Panel (CWP) due to improper sanitization of the 'userRes' POST parameter at the user endpoint. An unauthenticated remote attacker who knows or guesses a valid non-root username can execute arbitrary SQL queries with MySQL root privileges. By leveraging the 'INTO DUMPFILE' capability, an attacker can write a PHP webshell into the web-accessible Roundcube logs directory (/usr/local/cwpsrv/var/services/roundcube/logs/). This results in remote code execution (RCE) under the context of the 'cwpsvc' account. The issue is resolved in version 0.9.8.1225.
Affected products
- Control Web Panel (CWP) Control Web Panel before 0.9.8.1225
Timeline
- 2026-05-06: patched: Version 0.9.8.1225 released with security fix
- 2026-06-26: other: CVE identifier assigned
- 2026-07-01: disclosed: Public disclosure of the vulnerability