A critical blind SQL injection flaw tracked as CVE-2026-57517 affects Control Web Panel versions <= 0.9.8.1224 through the userRes POST parameter on the user endpoint. Public disclosure says the bug can be exploited remotely without authentication, although an attacker may need to know or guess a valid non-root username on the target instance. The issue carries a CVSS v3.1 score of 9.8 and allows arbitrary SQL execution against the backend database with MySQL root privileges.
The disclosed attack path shows the database access can be escalated into arbitrary file write using MySQL features such as INTO DUMPFILE, allowing a PHP webshell to be written into a web-accessible Roundcube logs directory and resulting in remote code execution as the cwpsvc account. The vulnerability was disclosed by Egidio Romano, and the vendor has fixed it in Control Web Panel 0.9.8.1225; administrators are being urged to upgrade immediately and apply the vendor's security updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A public advisory disclosed CVE-2026-57517 as a blind SQL injection vulnerability in Control Web Panel's userRes POST parameter. The disclosure described a path from arbitrary SQL execution as MySQL root to arbitrary file write and possible remote code execution as the cwpsvc account.
The SQL injection vulnerability affecting the userRes POST parameter in Control Web Panel was fixed in version 0.9.8.1225. The issue affected version 0.9.8.1224 and earlier and could be exploited remotely without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.