---
id: CVE-2026-57517
title: Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
summary: >-
  Control Web Panel before 0.9.8.1225 contains a blind SQL injection
  vulnerability that allows unauthenticated remote attackers to execute
  arbitrary SQL queries by submitting unsanitized input through the userRes POST
  parameter at the user…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-89
vendor: Control Web Panel
product: Control Web Panel
affected:
  - control_web_panel < 0.9.8.1225
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-01T15:52:38.937356Z'
exploitAvailable: true
published: '2026-07-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:24.554Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-57517'
references:
  - url: 'https://karmainsecurity.com/KIS-2026-12'
    label: Karma(In)Security Disclosure
  - url: 'https://control-webpanel.com/changelog#1773753427572-9bf81bf4-f2d2'
  - url: >-
      https://www.vulncheck.com/advisories/control-web-panel-blind-sql-injection-via-userres-parameter
tags:
  - cve.org
  - exploit-available
epss: 0.00963
epssPercentile: 0.60262
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/shinthink/CVE-2026-57517'
    - 'https://github.com/gagaltotal/CVE-2026-57517-CWP'
  checkedAt: '2026-10-01T19:59:31.763Z'
ingestedAt: '2026-10-01T19:58:57.572Z'
---

## Overview

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.

## Affected

- `control_web_panel < 0.9.8.1225`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
