


Perceptive Security
SOC/SIEM Consultancy

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries b…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 17:07:03
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
Control Web Panel versions before 0.9.8.1225 contain a blind SQL injection vulnerability in the userRes POST parameter at the user endpoint. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries without any authentication. Attackers can leverage MySQL root privileges obtained through the injection to write arbitrary files using the INTO DUMPFILE directive. This capability enables the deployment of a PHP webshell to the web-accessible roundcube logs directory. Successful exploitation results in remote code execution running as the cwpsvc account. The vulnerability chain effectively provides full server compromise from an unauthenticated network position. A patch is available in version 0.9.8.1225 and later.
Technical details
Mitigation steps:
Affected products:
Control Web Panel (CWP) before 0.9.8.1225
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57517
https://control-webpanel.com/changelog#1773753427572-9bf81bf4-f2d2
https://karmainsecurity.com/KIS-2026-12
https://www.vulncheck.com/advisories/control-web-panel-blind-sql-injection-via-userres-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
