2026-07-03HIGHCVE-2026-57517, Control Web Panel: pre-auth SQLi to RCE via INTO DUMPFILE (CVSS 9.8)
Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8)
cve · CVE-2026-57517 single-source-national-cert
Coverage
1
first 2026-07-03 → last 2026-07-03
Latest activity
2026-07-03
CVE-2026-57517, Control Web Panel: pre-auth SQLi to RCE via INTO DUMPFILE (CVSS 9.8)
Peak priority
high
1 high
Targets
technology
sectors: technology, education
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-57517, newest first. Check the date before acting on an older one.
- Update internet-facing Control Web Panel instances to 0.9.8.1225 or later now. The fix predates the public CVE by ~2 months, so any host not updated since May 2026 is exposed.2026-07-03CVE-2026-57517
- Treat patching as insufficient for compromise: check web-accessible directories under the CWP docroot (CCB names the Roundcube logs directory) for planted .php web shells before considering a previously-exposed host clean.2026-07-03CVE-2026-57517
- Hunt CWP/web-server access logs for SQL syntax (UNION, SLEEP(), INTO DUMPFILE/OUTFILE) in the userRes POST parameter, and alert on the cwpsvc service account spawning shell interpreters.2026-07-03CVE-2026-57517
Defender insights
What each entry about CVE-2026-57517 tells a defender to do, newest first.
Story timeline
- 2026-07-03CVE-2026-57517, Control Web Panel: pre-auth blind SQL injection to web-shell RCE (CVSS 9.8)
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce · ATT&CK page ↗
Entries about Control Web Panel pre-auth blind SQLi to web-shell RCE via INTO DUMPFILE (CVSS 9.8) (1)
Where this entity is cited
Source distribution
- ccb.belgium.be1 (50%)
- control-webpanel.com1 (50%)