CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
https://www.securityweek.com/cisa-warns-of-cwp-vulnerability-exploited-in-the-wild/