Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48614: Plesk XML API: Malicious User Can Write Root Files

CVE-2026-48614 CVE-2026-48614
Summary

An attacker with a Plesk account can write files with root access, potentially leading to server compromise. This is a serious issue, as it allows unauthorized access to sensitive server settings. To mitigate this, update Plesk to the latest version or apply the recommended patch.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
webpros plesk < 18.0.78
Original title
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege ...
Original description
An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.
nvd CVSS3.1 9.9
Vulnerability type
CWE-94 Code Injection
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026