Blind SQL Injection in Control Web Panel Affects Web Management Services
CVE-2026-57517
Key Information:
- Vendor
Control Web Panel
- Status
- Vendor
- CVE Published:
- 1 July 2026
Badges
What is CVE-2026-57517?
The vulnerability in Control Web Panel allows unauthenticated attackers to exploit a blind SQL injection flaw. By submitting unsanitized input through the userRes POST parameter at the user endpoint, attackers can execute arbitrary SQL queries. This exploit can lead to unauthorized access to MySQL root privileges, allowing attackers to write arbitrary files to the web-accessible directory. By leveraging the INTO DUMPFILE SQL command, an attacker can deploy a PHP web shell, facilitating remote code execution under the cwpsvc account.
Affected Version(s)
Control Web Panel 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
