Control Web Panel Blind SQLi to RCE – CVE-2026-57517
TL;DR: A blind SQL injection flaw in Control Web Panel (CWP), the free Linux server management panel formerly known as CentOS Web Panel, lets an unauthenticated attacker who can guess a valid username chain a database query into full remote code execution. A fix has existed since May 2026, but the flaw was only publicly disclosed on 1 July 2026 — with working proof-of-concept code already out in the open.
Key takeaways
- CVE-2026-57517 is a CVSS 9.8 (Critical) unauthenticated blind SQL injection in CWP’s
userResparameter, chainable to full remote code execution. - It affects Control Web Panel version 0.9.8.1224 and earlier; a fix has shipped in 0.9.8.1225.
- Public proof-of-concept exploit code is already circulating, even though no confirmed in-the-wild attacks have been reported yet.
- CWP runs on an estimated tens of thousands of internet-facing Linux servers as a free alternative to cPanel/Plesk, making unpatched instances an attractive target.
| CVSS Score | 9.8 (CVSS v3.1, base score — corroborated by multiple vulnerability trackers; full vector string not independently retrievable from NVD at time of writing) |
| CVSS Vector | Not confirmed at time of writing — see NVD entry for CVE-2026-57517 for the authoritative vector |
| Vulnerability Type | Blind SQL Injection escalating to Remote Code Execution (CWE-89) |
| Affected Products | Control Web Panel (CWP, formerly CentOS Web Panel) version 0.9.8.1224 and all prior versions |
| Attack Vector | Network — unauthenticated, no user interaction, but the attacker must know or correctly guess the username of a valid non-root CWP account |
| Actively Exploited | No confirmed in-the-wild exploitation as of 6 July 2026; not listed in the CISA KEV catalog at time of writing (public PoC exploit code is available) |
| Patch Available | Yes — fixed in CWP version 0.9.8.1225 (released May 2026, ahead of public disclosure) |
| Disclosure Date | 1 July 2026 (public); CVE ID requested and assigned 26 June 2026 |

What is CVE-2026-57517?
CVE-2026-57517 is a blind SQL injection vulnerability in Control Web Panel (CWP), a free server administration panel for Linux — the same tool many budget VPS and dedicated-server hosts use as a lightweight alternative to cPanel or Plesk. The flaw was found by researcher Egidio Romano (Karma(In)Security) and publicly disclosed on 1 July 2026 through the Full Disclosure mailing list, under the advisory reference KIS-2026-12.
The vulnerable code sits behind the userRes POST parameter, submitted to https://[CWP-host]:2083/[CWP-username]/. User input reaching that parameter isn’t properly sanitised before being used to build a SQL query, so a remote and entirely unauthenticated attacker can inject SQL syntax and run blind queries against the underlying database. On its own, blind SQLi is bad enough — the twist here is what an attacker can do with the access it grants.
How the Control Web Panel exploit works
In plain terms: the attacker doesn’t need a password, but they do need to know (or correctly guess) the username of an existing, non-root CWP account on the target server. Once they have that, they can send crafted requests to the vulnerable endpoint and use blind SQL injection techniques to interact with the database one bit of information at a time.
The part that turns this from “an annoying SQLi” into a full server compromise is the database privilege the query runs with. According to the discloser’s advisory, successful exploitation lets the attacker execute arbitrary SQL as the MySQL root user — and that account holds the global FILE privilege. That privilege lets a crafted query write arbitrary content to disk using MySQL’s file-output functions, such as SELECT ... INTO DUMPFILE.
Chained together, the attack path looks like this:
- Attacker identifies (or guesses) a valid CWP username.
- Attacker sends malicious input via the
userResparameter to trigger the blind SQL injection. - Injected queries run with MySQL root privileges, thanks to the
FILEprivilege. - The attacker uses
INTO DUMPFILE-style queries to write a PHP web shell into a directory that’s already served over HTTP — the advisory specifically names the Roundcube webmail logs path bundled with CWP as a writable, web-accessible location. - The attacker requests the planted PHP file directly, achieving remote code execution with the privileges of the
cwpsvcservice account.
NON-OPERATIONAL ILLUSTRATION ONLY — conceptual shape of the request chain, not working exploit code:POST /[CWP-username]/ HTTP/1.1Host: cwp-server:2083Content-Type: application/x-www-form-urlencodeduserRes=<blind-SQLi-payload-goes-here> -> injected query runs as MySQL root (has FILE privilege) -> attacker-controlled SELECT ... INTO DUMPFILE writes a .php file into a web-accessible logs directory -> attacker GETs the planted file to execute code as 'cwpsvc'
No working payload is reproduced here. A full proof-of-concept has been published by the discloser and is circulating publicly — see Sources below — which is precisely why unpatched, internet-facing CWP panels should be treated as urgent.

Is CVE-2026-57517 actively exploited?
As of 6 July 2026, ZeroDayHub has found no public reports of confirmed in-the-wild exploitation of CVE-2026-57517, and the CVE does not currently appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Some early aggregator write-ups implied a KEV listing; we could not verify that against CISA’s own catalog and have not repeated the claim.
What is confirmed is that working proof-of-concept exploit code was published alongside the disclosure. Historically, CWP and other hosting-panel vulnerabilities with public PoCs have moved from disclosure to mass scanning and opportunistic exploitation within days, so treat “not yet seen in the wild” as a narrow window rather than a reason to delay patching.

How to fix CVE-2026-57517: remediation & mitigation
Patch: Upgrade to Control Web Panel version 0.9.8.1225 or later. The fix has been available since May 2026, so most panels that keep up with routine updates should already be covered — this is a good moment to confirm rather than assume.
If you can’t patch immediately:
- Restrict access to the CWP admin port (default 2087) and the user panel port (default 2083) to trusted IP ranges or a VPN — don’t leave either exposed to the open internet.
- Put CWP behind a web application firewall or reverse proxy capable of inspecting and blocking suspicious
userResparameter values. - Audit and rotate CWP account usernames where feasible, since the attack depends on knowing a valid, guessable username.
- Review MySQL’s root account configuration; where operationally possible, tightening or monitoring use of the
FILEprivilege reduces the impact of any SQL injection, not just this one.
After patching: Rotate CWP and MySQL credentials, and specifically check the Roundcube webmail logs directory (and any other web-accessible, CWP-writable paths) for unexpected .php files or recently modified content. Terminate any suspicious active panel sessions.
Detection / IOCs: Look for unexpected .php files appearing under CWP-managed Roundcube log directories, unusual SELECT ... INTO DUMPFILE/OUTFILE activity in MySQL query logs, and repeated POST requests to /[username]/ endpoints carrying anomalous userRes values. No specific hashes, C2 domains, or named threat-actor indicators have been publicly attributed to this CVE as of this writing.
Frequently asked questions
Is Control Web Panel the same as cPanel? No. CWP (Control Web Panel, formerly CentOS Web Panel) is a separate, free server management panel for Linux, commonly used as a no-cost alternative to commercial panels like cPanel or Plesk. Don’t confuse advisories for the two products.
Do I need a password to be attacked? No — the attacker needs no valid password, but they do need to know or guess a legitimate non-root username on the target CWP instance. That’s a meaningful barrier, but usernames are often predictable (e.g. matching domain names or admin defaults), so it shouldn’t be relied on as a real mitigation.
Is my server affected if I’ve already updated recently? Only versions 0.9.8.1224 and earlier are vulnerable. If you’re running 0.9.8.1225 or later, you’re patched. If you’re unsure, check your CWP version in the admin dashboard and compare it against the changelog.
Why write this up if it’s not being exploited yet? Public, working proof-of-concept code plus a CVSS 9.8 severity rating is historically a strong leading indicator of imminent mass scanning. Patching now, while it’s “just” a disclosed flaw, is considerably cheaper than incident response after it’s weaponised at scale.
Sources & further reading
- [KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability — Full Disclosure mailing list (original advisory by discloser Egidio Romano)
- Karma(In)Security advisory index (KIS-2026-12), including the proof-of-concept reference
- NVD entry for CVE-2026-57517 (for the authoritative CVSS vector and CPE ranges)
- CISA Known Exploited Vulnerabilities Catalog (checked for listing status)
- Control Web Panel official changelog (confirms 0.9.8.1225 fix release)
ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.





Leave a Reply