---
schema: 1
kind: vulnerability
title: "CVE-2026-57517 — Control Web Panel: pre-auth blind SQL injection to web-shell RCE (CVSS 9.8)"
headline: "CVE-2026-57517 — Control Web Panel: pre-auth SQLi to RCE via INTO DUMPFILE (CVSS 9.8)"
summary: "CCB Belgium warned of CVE-2026-57517, a CVSS 9.8 pre-authentication blind SQL injection in the userRes parameter of Control Web Panel (CWP, formerly CentOS Web Panel) that chains via INTO DUMPFILE to a PHP web shell and full server compromise as the cwpsvc account. The fix (0.9.8.1225) shipped silently in May 2026, so any internet-facing CWP not updated since then is exposed; there is no confirmed in-the-wild exploitation yet, but the pre-auth, no-interaction nature and CWP's large exposed footprint make this patch-now."
discovered_at: "2026-07-03T18:25:00Z"
event_date: 2026-07-01
run_id: 2026-07-03T1809Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - sqli
  - pre-auth
  - patch-available
regions:
  - global
sectors:
  - technology
  - education
entities: []
cves:
  - id: CVE-2026-57517
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
    affected: "Control Web Panel < 0.9.8.1225"
    fixed: "0.9.8.1225"
sources:
  - url: "https://ccb.belgium.be/advisories/warning-cve-2026-57517-cvss-98-blind-sql-injection-control-web-panel-lets"
    publisher: Centre for Cybersecurity Belgium (CCB)
    role: primary
  - url: "https://control-webpanel.com/changelog"
    publisher: Control Web Panel vendor changelog
    role: corroborating
closed_sources: []
evidence:
  - quote: "This blind SQL injection vulnerability in the userRes parameter allows unauthenticated remote attackers to write arbitrary files to the underlying filesystem and achieve remote code execution."
    publisher: Centre for Cybersecurity Belgium (CCB)
  - quote: "There is no evidence of exploitation in the wild, however, the combination of critical severity, lack of authentication requirements, and CWP's large internet-facing footprint makes this a high-priority risk."
    publisher: Centre for Cybersecurity Belgium (CCB)
verification: single-source-national-cert
sourcing_note: "Primary technical detail is CCB Belgium's own advisory (national-CERT carve-out); the CVE is verified on NVD and the fix version/date is corroborated by the vendor changelog, but no second independent analysis of the flaw was available in-window."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Update internet-facing Control Web Panel instances to 0.9.8.1225 or later now.** The fix predates the public CVE by ~2 months, so any host not updated since May 2026 is exposed."
  - "Treat patching as insufficient for compromise: check web-accessible directories under the CWP docroot (CCB names the Roundcube logs directory) for planted .php web shells before considering a previously-exposed host clean."
  - "Hunt CWP/web-server access logs for SQL syntax (UNION, SLEEP(), INTO DUMPFILE/OUTFILE) in the userRes POST parameter, and alert on the cwpsvc service account spawning shell interpreters."
migrated_from: null
---

CCB Belgium published a fresh advisory for CVE-2026-57517, a pre-authentication blind SQL injection in Control Web Panel — the widely deployed Linux hosting/server-management platform formerly known as CentOS Web Panel ([CCB, 2026-07-03](https://ccb.belgium.be/advisories/warning-cve-2026-57517-cvss-98-blind-sql-injection-control-web-panel-lets)). The vulnerable input is the `userRes` POST parameter in the CWP user module; insufficient sanitisation lets an unauthenticated attacker inject SQL that runs with the backend database's privileges (CWE-89, CVSS 3.1 9.8 `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`; CVSS 4.0 9.3). The disclosed chain uses `INTO DUMPFILE` to blind-write an attacker-controlled PHP web shell into a web-accessible directory without needing query output or credentials; the shell then executes commands as the `cwpsvc` service account, yielding full server compromise. CCB states there is no evidence of in-the-wild exploitation yet but flags the pre-auth, no-interaction nature and CWP's large internet-facing footprint as a high-priority risk. The vendor changelog shows 0.9.8.1225 shipped 2026-05-06 — roughly two months before the public CVE disclosure on 2026-07-01 — so instances left unpatched since the silent fix remain exposed today ([Control Web Panel changelog, 2026-05-06](https://control-webpanel.com/changelog)). Mapped to `T1190 Exploit Public-Facing Application` for the SQLi vector and `T1505.003 Server Software Component: Web Shell` for the DUMPFILE-written shell. **Defender takeaway:** CWP has a history of becoming a mass-exploitation target once a pre-auth chain is public; patch immediately, and because the fix does not remediate prior compromise, retro-hunt exposed hosts for web shells and anomalous `cwpsvc` child processes rather than assuming a patched box is clean.
