Junglewise Threat Intelligence

CVE-2026-57517: Control Web Panel blind SQL injection in userRes parameter

CVE-2026-57517 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Technologies: Control Web Panel (CWP) Control Web Panel.

Executive brief

Control Web Panel, a server management interface for system administrators, contains a critical security flaw. An unauthenticated attacker can remotely execute commands on the server by sending specially crafted data to the user login endpoint. This could lead to a complete takeover of the server, unauthorized access to customer data, and full disruption of hosted services.

Technical details

A blind SQL injection vulnerability exists in Control Web Panel (CWP) due to improper sanitization of the 'userRes' POST parameter at the user endpoint. An unauthenticated remote attacker who knows or guesses a valid non-root username can execute arbitrary SQL queries with MySQL root privileges. By leveraging the 'INTO DUMPFILE' capability, an attacker can write a PHP webshell into the web-accessible Roundcube logs directory (/usr/local/cwpsrv/var/services/roundcube/logs/). This results in remote code execution (RCE) under the context of the 'cwpsvc' account. The issue is resolved in version 0.9.8.1225.

Affected products

  • Control Web Panel (CWP) Control Web Panel before 0.9.8.1225

Timeline

  • 2026-05-06: patched: Version 0.9.8.1225 released with security fix
  • 2026-06-26: other: CVE identifier assigned
  • 2026-07-01: disclosed: Public disclosure of the vulnerability

References