CVE-2026-57517Disclosure

HIGHCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (5 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection to write arbitrary files using INTO DUMPFILE, enabling deployment of a PHP webshell to the web-accessible roundcube logs directory and achieving remote code execution as the cwpsvc account.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 5 mentions (2026-07-03); latest day: 5
  • 14 total mentions across 5 days

Deep dive

Activity timeline14 mentions / 5d
01345Mentions · 2026-07-01: 1Mentions · 2026-07-03: 5Mentions · 2026-07-04: 2Mentions · 2026-07-06: 1Mentions · 2026-07-21: 5PoC Mentioned / Linked · 2026-07-03: 3PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-07-03: 2Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-07-21: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 5Technical Details · 2026-07-04: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-21: 507-0107-0307-0407-0607-21
Signal classification5 categories
Disclosure
750.0%
PoC
321.4%
Patch
214.3%
General
17.1%
Active Exploitation
17.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-07-011
Patch1
2026-07-035
Disclosure2Patch1PoC2
2026-07-042
General1PoC1
2026-07-061
Disclosure1
2026-07-215
Active Exploitation1Disclosure4
Full discourse14 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-57517: Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter Critical Vulnerability Alert! Control Web Panel is affected by CVE-2026-57517. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-57517 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-57517" Search Dork: app="Control Web Panel" Exposure: 896.4k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJDb250cm9sIFdlYiBQYW5lbCI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260703 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces a critical blind SQL injection vulnerability in Control Web Panel, linking to a detailed analysis and search resources but does not provide exploit code, evidence of active exploitation, or a patch.

    112138103.9K
    12.7K followersView on X
  • Netlas.io@Netlas_io
    PoC

    CVE-2026-57517: Blind SQL Injection in Control Web Panel, 9.8 rating 🔥 SQL Injection flow in Control Web Panel allows remote code execution. PoC is now available! 👉 https://nt.ls/biQe7

    Post summary

    The post announces a high‑severity blind SQL injection in Control Web Panel and provides a PoC, but does not discuss active exploitation or patches.

    0601051.6K
    7.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 Control Web Panel'de (eski adıyla Centos Web Panel) CVE-2026-57517 (CVSS 9.8) Güvenlik Açığı Kimlik doğrulaması gerektirmeyen Blind SQL Injection, userRes POST parametresi üzerinden tetikleniyor. Uygun yapılandırmalarda saldırgan, SELECT ... INTO DUMPFILE ile PHP webshell yükleyerek cwpsvc yetkileriyle RCE elde edebiliyor. 📌 Etkilenen sürümler: 0.9.8.1225 öncesi Public PoC mevcut olduğundan, mutlaka versiyon güncellemesi yapın.

    Post summary

    CVE‑2026‑57517 is a high‑severity blind SQL injection that can lead to RCE via a webshell; a public PoC exists, and users of versions before 0.9.8.1225 are urged to update immediately.

    1201341.7K
    2.2K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    PoC

    A public PoC is available for CVE-2026-57517, a critical CVSS 9.8 Control Web Panel SQLi flaw allowing unauthenticated remote code execution. #CVE202657517 #ControlWebPanel #SQLInjection #CyberSecurity #Vulnerability http://securityonline.info/cve-2026-57517-control-web-panel-sqli/

    Post summary

    The tweet announces a public PoC for CVE‑2026‑57517, a critical Control Web Panel SQL injection that enables unauthenticated remote code execution, and provides its CVSS 9.8 score.

    00130680
    12.9K followersView on X
  • moton@moton
    PoC

    Public PoC Exposes Control Web Panel SQLi CVE-2026-57517 (CVSS 9.8) - https://securityonline.info/cve-2026-57517-control-web-panel-sqli/

    Post summary

    A publicly available proof of concept reveals a critical SQL injection in Control Web Panel (CVE-2026‑57517), yet there is no indication of active exploitation or a patch at this time.

    00011114
    661 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    07:27 UTC: First exploit attempt in the wild. 0day Intel: 🚨 CVE-2026-57517: Control Web Panel &amp;lt; 0.9.8.1225 Blind SQL Injection via use

    Post summary

    The text reports the first in‑the‑wild exploit attempt for CVE‑2026‑57517, a blind SQL injection in Control Web Panel versions below 0.9.8.1225.

    1000038
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    04:30 UTC: Lyrie Sentinel flagged it. 0day Intel: 🚨 CVE-2026-57517: Control Web Panel &amp;lt; 0.9.8.1225 Blind SQL Injection via use

    Post summary

    A new CVE-2026-57517 has been flagged as a Blind SQL Injection in Control Web Panel versions below 0.9.8.1225; no PoC, exploit, or patch details are provided yet.

    1000036
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    04:41 UTC: Thread live on @lyrie_ai. 0day Intel: 🚨 CVE-2026-57517: Control Web Panel &amp;lt; 0.9.8.1225 Blind SQL Injection via use

    Post summary

    The tweet announces a blind SQL injection vulnerability (CVE-2026-57517) in Control Web Panel versions below 0.9.8.1225, but provides no PoC, exploit, or exploitation evidence.

    1000034
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    04:38 UTC: GPT-5 enrichment complete. 69 words. 1 citations. 0day Intel: 🚨 CVE-2026-57517: Control Web Panel &amp;lt; 0.9.8.1225 Blind SQL Injection via use

    Post summary

    A new CVE-2026-57517 is disclosed, revealing a blind SQL injection flaw in Control Web Panel versions below 0.9.8.1225, but no PoC, exploit code, or active exploitation details are provided.

    1000037
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    04:27 UTC: CVE-2026-57517 disclosed. 🚨 CVE-2026-57517: Control Web Panel &amp;lt; 0.9.8.1225 Blind SQL Injection via userRes Parameter Critical Vulnerability A

    Post summary

    The tweet announces the disclosure of CVE‑2026‑57517, a blind SQL injection flaw in Control Web Panel versions below 0.9.8.1225, with no PoC, exploit, or patch details provided.

    1000047
    326 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: CVE-2026-57517 CVSS 9.8 blind SQL injection in Control Web Panel lets unauthenticated attackers achieve RCE. More info at: https://ccb.belgium.be/advisories/warning-cve-2026-57517-cvss-98-blind-sql-injection-control-web-panel-lets. #Patch #Patch #Patch

    Post summary

    The post discloses CVE-2026-57517 as a blind SQL injection that allows unauthenticated RCE, referencing an advisory link for additional details.

    00001416
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Unauthenticated blind SQL injection to RCE in Control Web Panel user endpoint (CVE-2026-57517) Control Web Panel (CWP) is vulnerable to a blind SQL injection in the user endpoint via the userRes POST parameter, enabling attackers to execute arbitrary SQL against the backend database. The root cause is improper input validation/unsafe SQL query construction leading to SQL injection. Exploitation is unauthenticated and remote: an attacker sends crafted POST requests to the user endpoint to exfiltrate data and escalate within MySQL, then abuses INTO DUMPFILE to write a PHP payload into a web-accessible Roundcube logs directory. Impact is full compromise of the server via webshell drop and remote code execution as the cwpsvc account, with potential database takeover and data theft. 👉 Affected: Control Web Panel < 0.9.8.1225 | Upgrade to 0.9.8.1225

    Post summary

    Vulnerability CVE-2026-57517 allows unauthenticated blind SQL injection leading to remote code execution in Control Web Panel; upgrading to version 0.9.8.1225 mitigates the flaw.

    00001112
    232 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Control Web Panel(CWP)にSQLインジェクションが可能な脆弱性-(CVE-2026-57517) https://rocket-boys.co.jp/security-measures-lab/control-web-panel-cwp-sql-injection-cve-2026-57517/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces a new CVE (CVE-2026-57517) that allows SQL injection in Control Web Panel (CWP), providing basic technical detail of the vulnerability.

    00000123
    457 followersView on X
  • siri@fu4k1@sirifu4k1
    General

    @ridvanyagli anywhere about CVE-2026-57517 poc ?

    Post summary

    The text is a brief query asking whether anyone knows of a proof of concept for CVE‑2026‑57517, with no additional information provided.

    00000137
    7.0K followersView on X

Explore more