A blind SQL injection in Control Web Panel’s userRes parameter lets attackers with a guessable username gain MySQL root access, enabling full server takeover via a planted PHP webshell.
Read more about Emerging Threat: (CVE-2026-57517) Control Web Panel Remote Code Execution via SQL Injection