Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48614: Plesk XML API: Malicious User Can Write Root Files
CVE-2026-48614
CVE-2026-48614
Summary
An attacker with a Plesk account can write files with root access, potentially leading to server compromise. This is a serious issue, as it allows unauthorized access to sensitive server settings. To mitigate this, update Plesk to the latest version or apply the recommended patch.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | plesk | < 18.0.78 |
Original title
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege ...
Original description
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
nvd CVSS3.1
9.9
Vulnerability type
CWE-94
Code Injection
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026