CVE-2026-57517: Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter

Published Jul 1, 2026
·
Updated

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.

Affected Software

1 affected component
Control Web Panel Control Web Panel<0.9.8.1225

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Control Web Panel to a version that resolves this vulnerability.

    Fixed in 0.9.8.1225
  2. Compensating control

    Restrict access so unauthenticated remote attackers cannot reach the Control Web Panel user endpoint that accepts the unsanitized input via the userRes POST parameter (e.g., via network/WAF/ACL)

Event History

Jul 1, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-57517?

CVE-2026-57517 has a severity score of 9.3, indicating it is critical.

2

What type of vulnerability is associated with CVE-2026-57517?

CVE-2026-57517 is a blind SQL injection vulnerability that affects Control Web Panel.

3

How can I fix CVE-2026-57517?

To fix CVE-2026-57517, update Control Web Panel to version 0.9.8.1225 or later.

4

Who is affected by CVE-2026-57517?

Users of Control Web Panel versions prior to 0.9.8.1225 are at risk from CVE-2026-57517.

5

What impact can CVE-2026-57517 have on a system?

CVE-2026-57517 allows unauthenticated attackers to execute arbitrary SQL queries, potentially compromising database security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203