Control Web Panel Security Precaution: Temporary Control Panel Access Restrictions on VPS and Dedicated Servers

Update (September 14, 2026): CWP has released version 1.12, which patches the vulnerabilities behind this precaution. After testing the update, we have reopened the CWP panel ports on VPS and Dedicated servers running version 1.12. If your server was updated, you can log in to the CWP Admin and User panels as usual with no further action. A small number of servers could not be updated to version 1.12, and their ports remain closed. If you still cannot reach CWP, see If Your CWP Access Is Still Restricted below.

On September 2, 2026, as a security precaution, InMotion Hosting temporarily closed the firewall ports used to reach the Control Web Panel (CWP) Admin and User panels on CWP VPS and Dedicated servers. We took this step to protect your server from unauthorized access while we investigated suspicious activity targeting CWP. Your websites, email, and databases remained online and unaffected throughout.

This restriction has now been lifted on servers running CWP 1.12 or later. If your CWP panels are still unreachable, your server has not yet been updated. Send us the public IP address you connect from, and we will add it to your server’s firewall allowlist so you can log in and update. Details on what to send and where are below.

What Happened

Our security team identified unauthorized activity targeting servers running Control Web Panel. This included a weakness in the WordPress autologin feature that CWP added in version 0.9.8.1225 in May 2026. The flaw could be abused to log in to a WordPress site without valid credentials. CWP released a fix in version 1.12 on September 8, 2026.

While the investigation was ongoing, we treated all CWP servers as potentially exposed until a fix was available. Closing the CWP control panel to the public internet was the fastest way to protect every affected server at once.

What We Did

We removed the following ports from the inbound rules in the ConfigServer Security & Firewall (CSF) configuration on CWP VPS and Dedicated servers:

  • 2082 and 2083 (CWP User panel)
  • 2030, 2031, 2086, and 2087 (CWP Admin panel)

With these ports closed, a server no longer accepts connections to the CWP panels from the public internet. The panels themselves keep running, but they are unreachable until an IP address is added to the firewall allowlist.

Once CWP 1.12 was available, we tested the update and confirmed it was safe to restore access. We then reopened the CWP ports on every VPS and Dedicated server that had been updated to version 1.12. Servers that could not be updated, for example because the disk was full, were left with the ports closed to keep them protected.

What This Means for You

  • If your server is running CWP 1.12: the CWP Admin and User panels are reachable again from any IP address. No action is needed.
  • If your server could not be updated: attempts to open the CWP Admin or User panel will still time out in your browser until we add your IP address to the allowlist. Follow the steps in the next section.
  • Your websites, applications, databases, and email continue to operate normally in either case.
  • SSH, SFTP, FTP, and webmail access were never affected.
  • Your Account Management Panel (AMP) login was never affected.

If Your CWP Access Is Still Restricted

If you cannot reach your CWP panels, your server is one of the few that could not be updated to CWP 1.12. Our team will add your IP address to your server’s firewall allowlist so you can log in, resolve whatever is blocking the update (a full disk is the most common cause), and bring CWP up to date. To make this a single round trip, include everything below in one request.

What to send us

  • Your public IPv4 address. This is the IP address your internet connection uses, not your server’s IP. To find it, open a browser on the device you use to manage your server and search “What is my IP.” The IPv4 address is the result we need.
  • Every location you manage CWP from. If you log in from home and from an office, or if a developer or agency manages the server for you, include each public IP address in the same request.
  • Your server hostname or primary domain. This lets us identify the correct server quickly, especially if you have more than one.

Note: Many home and mobile internet connections use a dynamic IP address that changes over time. If your CWP access stops working again later, check your public IP address and send us the new one. A static IP address from your internet provider, or a VPN with a fixed exit address, will avoid repeat requests.

Where to send it

The whole process takes a few minutes and does not require waiting for an agent:

  1. Log in to your Account Management Panel (AMP).
  2. Start a new message with our team using the chat widget.
  3. Enter your public IPv4 address, along with any other IPv4 addresses you connect from.
  4. Submit the request. You do not need to stay in the chat afterward.
  5. Follow along on our Status page for updates.

Important: We handle allowlist requests in the order received. We cannot expedite individual requests. Submitting the same request more than once, or through another channel such as a support ticket or email, does not move it forward. Submit once, and we will confirm by email when your IP address has been added.

If you have root SSH access

This change does not affect SSH access. If you are comfortable managing your own server, you can allow your IP address yourself. Log in via SSH as root and run the following command, replacing the example address with your public IP address:

csf -a 203.0.113.10

The rule takes effect immediately, and you can log in to CWP right away. Only add addresses you control. Do not re-open the CWP ports to all traffic in the CSF configuration until your server is running CWP 1.12, as that removes the protection this change provides.

Once you have cleared the blocker, you can also run the CWP update yourself from the same root SSH session:

sh /scripts/update_cwp

After the update finishes, the CWP Admin panel dashboard shows the installed version. When it reports 1.12 or later, let us know through the AMP chat and we will reopen the CWP ports on your server.

Keeping Your Server Protected

CWP normally updates itself through a scheduled task, so most servers received version 1.12 without any action. A server that is stuck on an older version usually has something preventing the update, such as a full disk, and is worth checking. Keeping CWP current is the best protection against issues like this one. We will update this article if anything changes. For live updates, visit status.inmotionhosting.com.

Your security and the integrity of your service are our top priority. Thank you for your patience while we worked to keep your server protected.

Summarize and Research with AI
Share on Social Media
Derrell Willis
Derrell Willis Manager, Developer Relations

More Articles by Derrell